manifest-audit
Verification PAYMENT-READYpayment-ready until 2026-09-30
Pay-per-call dependency audit for coding agents. POST a package.json, a requirements.txt, or npm and PyPI package lists and get per-package latest version and publish date, whether a pin is behind, license, deprecation or yanked status, weekly npm downloads, and OSV vulnerabilities with severity and first fixed version. Up to 50 packages per call. $0.01 whole manifest; $0.005 npm-only, PyPI-only, vulns-only. USDC on Base via the Coinbase facilitator, x402 v2, no API keys, no LLM.
Pay from $0.005 to $0.01 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.
listed 2026-09-23 · no on-chain settlement recorded yet
VERDICT
ranking generation 3solid 88/100 #8 of 101 in Verification by measured score
What the score read on this service: status online, 100% uptime 24h (no 30d window yet), 130ms response p95, x402 compliance 14 of 14, $0.005 price against the category, on-chain traction measured. Each of those is measured, and each is published in full below.
The score comes from our own monitoring, never from reviews, operator claims, or a language model: reliability, x402 compliance, price against the category, a deterministic risk flag, and a small on-chain traction term, weighted by ranking generation 3. It is not placement anyone can buy: the paid verify tier is reported beside it and is not one of its inputs. Every component below stays published and read-only.
It is a score inside Verification, and only there: price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, which here means 101 listings, this one among them. That set is wider than the 101 the position above is counted against, because a listing we have measured too little of to rank still sits in the field the price and the speed are normalized over. The same service in a different field would read differently. The same engine answers GET /api/v1/best, and asked for a different pool (the whole directory, or another filter) it returns a different number for this service under this same ranking generation. Neither is more correct: they answer different questions, and the methodology states which is which.
Bands on the 0 to 100 measured score: strong at 93 and above, solid from 75, mixed from 55, weak below 55. Price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, so the score places a service in its own field.
ALTERNATIVES IN VERIFICATION
Other Verification services in this directory, ordered by the same measured score. The figures are ours: 30-day uptime from our own probes, 30-day settlement volume read on-chain (a conservative undercount, and null where we cannot measure it, never a zero).
| SERVICE | BAND | SCORE | UPTIME 30D | VOL 30D |
|---|---|---|---|---|
| scvd.store — evidence observatory for the x402 economy | strong | 94 | 100% | $941.05 |
| Rubric Protocol — Post-Quantum AI Attestation | solid | 92 | 99.8% | $31.20 |
| Enclave402 | solid | 89 | --- | $0 |
| ARAKEL Machine Evidence Network | solid | 89 | 98.7% | $0.10 |
| LION — Verified Company & Compliance Data | solid | 89 | 100% | $7.25 |
ASSESSMENT
updated 1h agoThe parts the verdict above is computed from, each with its proof. Click any chip. Measured values stay read-only; unknown is honest, and an unknown is never counted as a zero.
reliability 100%
- uptime 24h
- -
- uptime 7d
- -
- uptime 30d
- -
- uptime 90d
- -
- response p95
- 130ms
- avg response
- 130ms
- total checks
- 1
Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.
compliance A (14/14)
14 of 14 x402 conformance checks pass. Full checklist below.
price $0.005 to $0.01 (p28 in Verification)
- price (min)
- $0.005
- price (max)
- $0.01
- category percentile (min)
- p28 in Verification
- category percentile (max)
- p22 in Verification
- endpoints / prices
- 4 / 2
- model
- tiered
- stability
- 100%
risk clean
No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.
- domain age
- -
- registrar
- -
- hosting
- custom
- domain created
- ---
Identity facts, not a risk score.
traction $0.00 30d · 0 buyers
- volume 30d
- $0.00
- buyers 30d
- 0
- settlements 30d
- 0
- measured since
- --- (start of our harvest window)
- last settlement
- ---
- top buyer share
- -
- trend 7d vs 30d
- -
- networks
- eip155:8453
- volume all-time
- $0
- settlements all-time
- 0
- median settlement 30d
- -
- max settlement 30d
- -
- settled via
- -
Conservative undercount: only USDC settlements via facilitators we measure are counted. A measured floor, not an estimate.
Top buyer share is a concentration signal, not part of the ranking score.
WHAT IT DOES
ai-derivedNo AI synthesis has been produced for this service yet.
ENDPOINTS
| METHOD | PATH | DESCRIPTION | PRICE | NETWORK | ASSET | 402 CHANNEL |
|---|---|---|---|---|---|---|
| POST | /v1/audit | $0.01 | Base | USDC | header | |
| POST | /v1/npm | $0.005 | Base | USDC | header | |
| POST | /v1/pypi | $0.005 | Base | USDC | header | |
| POST | /v1/vulns | $0.005 | Base | USDC | header |
REQUEST / RESPONSE EXAMPLE
An unpaid request to POST /v1/audit returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.
curl -i -X POST 'https://audit.152-53-82-29.sslip.io/v1/audit'
// 402 response (captured by monitor) · 4 payloads · click to expand
[
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x9Ea52806dB0b25a8130D2b210D5336eC1DCFBa0e",
"amount": "5000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://audit.152-53-82-29.sslip.io/v1/pypi",
"tags": [
"pypi",
"python",
"pip",
"vulnerabilities",
"requirements.txt"
],
"mimeType": "application/json",
"description": "Check Python packages from PyPI before you pip install or bump versions. Send {\"packages\":[\"requests==2.25.0\",\"flask>=2.0\"]} or {\"requirements\":\"<requirements.txt text>\"}, up to 50 packages. Per package: latest release and date, whether a pinned version is behind, license, yanked status, requires_python, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM.",
"serviceName": "manifest-audit"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"packages": [
"requests==2.25.0",
"flask>=2.0"
]
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"rows": [
{
"name": "flask",
"notes": [
"range \">=2.0\" audited at latest"
],
"behind": null,
"latest": "3.1.2",
"pinned": null,
"license": "BSD-3-Clause",
"ecosystem": "pypi",
"requested": ">=2.0",
"deprecated": false,
"max_severity": null,
"vulnerabilities": [],
"latest_published": "2025-08-19T00:00:00Z",
"weekly_downloads": null,
"vulnerability_count": 0
}
],
"sources": [
"api.deps.dev",
"api.osv.dev",
"registry.npmjs.org",
"api.npmjs.org",
"pypi.org"
],
"summary": {
"packages": 2,
"unpinned": 1,
"deprecated": 0,
"behind_latest": 1,
"lookup_errors": 0,
"with_vulnerabilities": 1
},
"elapsed_ms": 1800,
"generated_at": "2026-09-22T23:00:00Z",
"max_packages": 50
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"properties": {
"packages": {
"type": "array",
"items": {
"type": "string"
},
"description": "PyPI requirement lines"
},
"requirements": {
"type": "string",
"description": "Raw requirements.txt text"
}
}
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"rows": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"notes": {
"type": "array",
"items": {
"type": "string"
}
},
"behind": {
"type": [
"boolean",
"null"
]
},
"latest": {
"type": [
"string",
"null"
]
},
"pinned": {
"type": [
"string",
"null"
]
},
"license": {
"type": [
"string",
"null"
]
},
"ecosystem": {
"type": "string"
},
"requested": {
"type": [
"string",
"null"
]
},
"deprecated": {
"type": [
"boolean",
"string",
"null"
]
},
"max_severity": {
"type": [
"string",
"null"
]
},
"vulnerabilities": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"aliases": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "string"
},
"fixed_in": {
"type": [
"string",
"null"
]
},
"severity": {
"type": "string"
}
}
}
},
"latest_published": {
"type": [
"string",
"null"
]
},
"weekly_downloads": {
"type": [
"integer",
"null"
]
},
"vulnerability_count": {
"type": "integer"
}
}
}
},
"sources": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "object",
"properties": {
"packages": {
"type": "integer"
},
"unpinned": {
"type": "integer"
},
"deprecated": {
"type": "integer"
},
"behind_latest": {
"type": "integer"
},
"lookup_errors": {
"type": "integer"
},
"with_vulnerabilities": {
"type": "integer"
}
}
},
"elapsed_ms": {
"type": "integer"
}
}
}
}
}
}
}
}
},
"x402Version": 2
},
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x9Ea52806dB0b25a8130D2b210D5336eC1DCFBa0e",
"amount": "10000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://audit.152-53-82-29.sslip.io/v1/audit",
"tags": [
"dependency-audit",
"package.json",
"requirements.txt",
"vulnerabilities",
"licenses"
],
"mimeType": "application/json",
"description": "Audit a whole dependency manifest in one call before installing or upgrading. Send a package.json, a requirements.txt, or npm and PyPI package lists (up to 50 packages). Per dependency: latest version and publish date, whether your pin is behind, license, deprecation or yanked status, weekly npm downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM. Use before adding or bumping deps or when reviewing a lockfile change.",
"serviceName": "manifest-audit"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"npm": [
"[email protected]",
"express@^4.18.0",
"left-pad"
],
"pypi": [
"requests==2.25.0",
"flask>=2.0"
]
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"rows": [
{
"name": "lodash",
"notes": [],
"behind": true,
"latest": "4.18.1",
"pinned": "4.17.20",
"license": "MIT",
"ecosystem": "npm",
"requested": "4.17.20",
"deprecated": false,
"max_severity": "HIGH",
"vulnerabilities": [
{
"id": "GHSA-35jh-r3h4-6jhm",
"aliases": [
"CVE-2021-23337"
],
"summary": "Command injection in lodash",
"fixed_in": "4.17.21",
"severity": "HIGH"
}
],
"latest_published": "2026-04-01T21:01:20Z",
"weekly_downloads": 128527290,
"vulnerability_count": 5
},
{
"name": "flask",
"notes": [
"range \">=2.0\" audited at latest"
],
"behind": null,
"latest": "3.1.2",
"pinned": null,
"license": "BSD-3-Clause",
"ecosystem": "pypi",
"requested": ">=2.0",
"deprecated": false,
"max_severity": null,
"vulnerabilities": [],
"latest_published": "2025-08-19T00:00:00Z",
"weekly_downloads": null,
"vulnerability_count": 0
}
],
"sources": [
"api.deps.dev",
"api.osv.dev",
"registry.npmjs.org",
"api.npmjs.org",
"pypi.org"
],
"summary": {
"packages": 2,
"unpinned": 1,
"deprecated": 0,
"behind_latest": 1,
"lookup_errors": 0,
"with_vulnerabilities": 1
},
"elapsed_ms": 1800,
"generated_at": "2026-09-22T23:00:00Z",
"max_packages": 50
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"properties": {
"npm": {
"type": "array",
"items": {
"type": "string"
},
"description": "npm packages as name or name@version"
},
"pypi": {
"type": "array",
"items": {
"type": "string"
},
"description": "PyPI requirement lines, for example requests==2.25.0"
},
"manifest": {
"type": "string",
"description": "Raw package.json or requirements.txt text"
},
"ecosystem": {
"enum": [
"npm",
"pypi"
],
"type": "string",
"description": "Required with `manifest` when it is a requirements.txt"
},
"dependencies": {
"type": "object",
"description": "package.json dependencies map"
},
"devDependencies": {
"type": "object",
"description": "package.json devDependencies map"
}
},
"description": "Send any one of: a package.json object, a requirements.txt string in `manifest`, or explicit `npm` and `pypi` lists."
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"rows": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"notes": {
"type": "array",
"items": {
"type": "string"
}
},
"behind": {
"type": [
"boolean",
"null"
]
},
"latest": {
"type": [
"string",
"null"
]
},
"pinned": {
"type": [
"string",
"null"
]
},
"license": {
"type": [
"string",
"null"
]
},
"ecosystem": {
"type": "string"
},
"requested": {
"type": [
"string",
"null"
]
},
"deprecated": {
"type": [
"boolean",
"string",
"null"
]
},
"max_severity": {
"type": [
"string",
"null"
]
},
"vulnerabilities": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"aliases": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "string"
},
"fixed_in": {
"type": [
"string",
"null"
]
},
"severity": {
"type": "string"
}
}
}
},
"latest_published": {
"type": [
"string",
"null"
]
},
"weekly_downloads": {
"type": [
"integer",
"null"
]
},
"vulnerability_count": {
"type": "integer"
}
}
}
},
"sources": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "object",
"properties": {
"packages": {
"type": "integer"
},
"unpinned": {
"type": "integer"
},
"deprecated": {
"type": "integer"
},
"behind_latest": {
"type": "integer"
},
"lookup_errors": {
"type": "integer"
},
"with_vulnerabilities": {
"type": "integer"
}
}
},
"elapsed_ms": {
"type": "integer"
}
}
}
}
}
}
}
}
},
"x402Version": 2
},
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x9Ea52806dB0b25a8130D2b210D5336eC1DCFBa0e",
"amount": "5000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://audit.152-53-82-29.sslip.io/v1/npm",
"tags": [
"npm",
"package-check",
"vulnerabilities",
"deprecated",
"license"
],
"mimeType": "application/json",
"description": "Check npm packages before you install or upgrade. Send {\"packages\":[\"[email protected]\",\"express\"]} or a package.json (dependencies and devDependencies), up to 50 packages. Per package: latest version and publish date, whether a pinned version is behind, license, deprecation notice, weekly downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic registry data, no LLM.",
"serviceName": "manifest-audit"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"packages": [
"[email protected]",
"express",
"left-pad"
]
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"rows": [
{
"name": "lodash",
"notes": [],
"behind": true,
"latest": "4.18.1",
"pinned": "4.17.20",
"license": "MIT",
"ecosystem": "npm",
"requested": "4.17.20",
"deprecated": false,
"max_severity": "HIGH",
"vulnerabilities": [
{
"id": "GHSA-35jh-r3h4-6jhm",
"aliases": [
"CVE-2021-23337"
],
"summary": "Command injection in lodash",
"fixed_in": "4.17.21",
"severity": "HIGH"
}
],
"latest_published": "2026-04-01T21:01:20Z",
"weekly_downloads": 128527290,
"vulnerability_count": 5
},
{
"name": "flask",
"notes": [
"range \">=2.0\" audited at latest"
],
"behind": null,
"latest": "3.1.2",
"pinned": null,
"license": "BSD-3-Clause",
"ecosystem": "pypi",
"requested": ">=2.0",
"deprecated": false,
"max_severity": null,
"vulnerabilities": [],
"latest_published": "2025-08-19T00:00:00Z",
"weekly_downloads": null,
"vulnerability_count": 0
}
],
"sources": [
"api.deps.dev",
"api.osv.dev",
"registry.npmjs.org",
"api.npmjs.org",
"pypi.org"
],
"summary": {
"packages": 2,
"unpinned": 1,
"deprecated": 0,
"behind_latest": 1,
"lookup_errors": 0,
"with_vulnerabilities": 1
},
"elapsed_ms": 1800,
"generated_at": "2026-09-22T23:00:00Z",
"max_packages": 50
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"properties": {
"packages": {
"type": "array",
"items": {
"type": "string"
},
"description": "npm packages as name or name@version"
},
"dependencies": {
"type": "object"
},
"devDependencies": {
"type": "object"
}
}
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"rows": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"notes": {
"type": "array",
"items": {
"type": "string"
}
},
"behind": {
"type": [
"boolean",
"null"
]
},
"latest": {
"type": [
"string",
"null"
]
},
"pinned": {
"type": [
"string",
"null"
]
},
"license": {
"type": [
"string",
"null"
]
},
"ecosystem": {
"type": "string"
},
"requested": {
"type": [
"string",
"null"
]
},
"deprecated": {
"type": [
"boolean",
"string",
"null"
]
},
"max_severity": {
"type": [
"string",
"null"
]
},
"vulnerabilities": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"aliases": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "string"
},
"fixed_in": {
"type": [
"string",
"null"
]
},
"severity": {
"type": "string"
}
}
}
},
"latest_published": {
"type": [
"string",
"null"
]
},
"weekly_downloads": {
"type": [
"integer",
"null"
]
},
"vulnerability_count": {
"type": "integer"
}
}
}
},
"sources": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "object",
"properties": {
"packages": {
"type": "integer"
},
"unpinned": {
"type": "integer"
},
"deprecated": {
"type": "integer"
},
"behind_latest": {
"type": "integer"
},
"lookup_errors": {
"type": "integer"
},
"with_vulnerabilities": {
"type": "integer"
}
}
},
"elapsed_ms": {
"type": "integer"
}
}
}
}
}
}
}
}
},
"x402Version": 2
},
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x9Ea52806dB0b25a8130D2b210D5336eC1DCFBa0e",
"amount": "5000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://audit.152-53-82-29.sslip.io/v1/vulns",
"tags": [
"vulnerabilities",
"cve",
"osv",
"security",
"sca"
],
"mimeType": "application/json",
"description": "Known vulnerabilities for a list of dependencies, npm and PyPI, in one call. Send {\"npm\":[\"[email protected]\"],\"pypi\":[\"django==3.2.0\"]} or a package.json or requirements.txt, up to 50 packages. Returns only packages that have advisories: OSV and GHSA ids, CVE aliases, severity, summary, and the first fixed version, plus counts. Unpinned packages are checked at their latest version. Deterministic OSV data, no LLM.",
"serviceName": "manifest-audit"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"npm": [
"[email protected]"
],
"pypi": [
"django==3.2.0"
]
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"rows": [
{
"name": "django",
"ecosystem": "pypi",
"max_severity": "CRITICAL",
"version_checked": "3.2.0",
"vulnerabilities": [
{
"id": "GHSA-2gwj-7jmv-h26r",
"aliases": [
"CVE-2023-31047"
],
"summary": "Django bypass of validation when uploading multiple files",
"fixed_in": "3.2.19",
"severity": "CRITICAL"
}
],
"vulnerability_count": 63
}
],
"sources": [
"api.osv.dev",
"api.deps.dev"
],
"summary": {
"packages": 2,
"max_severity": "CRITICAL",
"with_vulnerabilities": 1,
"total_vulnerabilities": 63
},
"elapsed_ms": 900
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"properties": {
"npm": {
"type": "array",
"items": {
"type": "string"
}
},
"pypi": {
"type": "array",
"items": {
"type": "string"
}
},
"manifest": {
"type": "string"
},
"ecosystem": {
"enum": [
"npm",
"pypi"
],
"type": "string"
}
}
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"rows": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"ecosystem": {
"type": "string"
},
"max_severity": {
"type": [
"string",
"null"
]
},
"version_checked": {
"type": [
"string",
"null"
]
},
"vulnerabilities": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"aliases": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "string"
},
"fixed_in": {
"type": [
"string",
"null"
]
},
"severity": {
"type": "string"
}
}
}
},
"vulnerability_count": {
"type": "integer"
}
}
}
},
"sources": {
"type": "array",
"items": {
"type": "string"
}
},
"summary": {
"type": "object",
"properties": {
"packages": {
"type": "integer"
},
"max_severity": {
"type": [
"string",
"null"
]
},
"with_vulnerabilities": {
"type": "integer"
},
"total_vulnerabilities": {
"type": "integer"
}
}
},
"elapsed_ms": {
"type": "integer"
}
}
}
}
}
}
}
}
},
"x402Version": 2
}
] OVER TIME
All charts use the 30d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/manifest-audit/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.
Median across 4 endpoints. Use the selector to isolate one.
checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression
COMPLIANCE
14/14 checks pass · grade Alast 402 captured 2026-09-23 · last up 2026-09-23
- 402 payload captured
- accepts[] array present
- payTo address recoverable
- payTo at accepts[0].payTo (conformant shape)
- payTo is a valid on-chain address
- atomic price declared
- atomic price in a sane range
- asset (token) address declared
- network resolves to CAIP-2
- payment scheme declared
- served over HTTPS
- declares the current x402 version (2)
- EIP-712 domain parameters present on every EVM entry
- x402 v2 envelope delivered in the payment-required header
SITE PILLARS
- homepage reachable
- openapi doc
- pricing page
- llms.txt
- robots.txt
- terms page
recent checks (6) live · click to expand
EMBED THIS BADGE
<a href="https://x402-list.com/services/manifest-audit?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/manifest-audit.svg" alt="manifest-audit listed on x402-list" height="28"> </a>
[](https://x402-list.com/services/manifest-audit?utm_source=badge&utm_medium=referral&utm_campaign=embed)
<a href="https://x402-list.com/services/manifest-audit?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/manifest-audit.svg?data=uptime" alt="manifest-audit uptime on x402-list" height="28"> </a>