OWASP Dependency-Check with Gradle: Triage Matches, Not Just Scores
OWASP Dependency-Check identifies potential known-vulnerability matches in dependencies. A reported match needs applicability review: package.
Check your Gradle dependencies against a curated list of known-vulnerable library versions. (Not a full CVE database.)
Gradle Vulnerability Scanner is part of APKLint, an online toolkit for inspecting Android APK files. Check your Gradle dependencies against a curated list of known-vulnerable library versions. (Not a full CVE database.). Paste your build.gradle or libs.versions.toml in your browser to view the relevant details; results reflect what you paste.
Check your Gradle dependencies against a curated list of known-vulnerable library versions. (Not a full CVE database.)
Gradle Vulnerability Scanner is part of APKLint’s code quality toolkit — Static analysis for Kotlin, Java, and your Gradle build. It’s free to use and needs no account.
Your privacy is the default: what you submit is processed on our servers over an encrypted connection for that request only — it isn’t written to file or object storage, and never shared.
Good to know: Uses a curated list of well-known vulnerable versions — it is not a full CVE/OSV database scan.
Every tool is free with no login and no paywall. Reasonable file and input limits keep the free service stable.
A clean, focused interface with no third-party ad banners cluttering your results.
What you submit is processed for the request only — it isn't written to file or object storage, and never shared.
A pure-Python Gradle and dependency parser.
Start immediately — no account, login, or email required.
Runs in any modern browser, on desktop or mobile.
Check your Gradle dependencies against a curated list of known-vulnerable library versions. (Not a full CVE database.)
No. It checks a curated set of widely-known vulnerable versions. For complete coverage, run OSV-Scanner or Trivy with your lockfiles.
Yes. Every tool on APKLint is completely free, with no sign-up and no account.
What you submit is sent to our backend over an encrypted connection only to produce your result. It isn't written to file storage, used for analytics, or shared.
Paste your build.gradle / build.gradle.kts dependency block.
All product names, logos, and trademarks are property of their respective owners. APKLint is an independent toolset and is not affiliated with, endorsed by, or sponsored by Google, Android, or any other party.