Weedout watches your dependency manifests and only tells you about vulnerabilities that are actually exploited in the wild or actually reachable in what you ship.
Hey Product Hunt 👋
I built Weedout because dependency scanners can generate a ton of vulnerability alerts without telling you which ones actually matter to your application.
I wanted something simpler: scan a project, understand which vulnerable dependencies are actually relevant, and focus on what needs fixing instead of chasing noise.
Weedout started as a small solo project and I've been shipping and improving it based on real usage and feedback.
I'd especially love feedback from developers who already use tools like npm audit, Dependabot, Snyk, or other dependency scanners.
If something sucks, tell me. That's genuinely more useful to me than “looks great.” 😄