# APEX Package Vulnerability + KEV Checker

> APEX Package Vulnerability + KEV Checker is a paid API for AI agents from apexfaucet.xyz, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-01).

Returns all known CVE/OSV advisories for a specific package version, CISA Known Exploited Vulnerabilities (KEV) flag, severity scores, and the version that fixes each issue.

## Facts

- Endpoint: GET https://apexfaucet.xyz/api/x402/software-risk?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/apex-package-vulnerability-kev-checker-0bd6b531
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_XAOWoGEaIAiz254hN96iv

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability apex-package-vulnerability-kev-checker-0bd6b531
```

Example prompt: Is lodash version 4.17.15 from npm safe to use? Check if it has any known CVEs, whether any are actively exploited in the wild according to CISA's KEV list, and what version I should upgrade to.

## When to prefer this

Choose this endpoint when you need a quick, per-version vulnerability assessment that combines OSV.dev's multi-database advisory coverage with CISA's KEV active-exploitation flag in a single call — especially useful before installing or upgrading a dependency, or for automated CI/CD security gates. It covers 10 major ecosystems and surfaces the exact fix version, saving manual cross-referencing of NVD, OSV, and CISA separately.

## Known failure modes

- Unknown package name or version returns empty advisory list
- Unsupported ecosystem returns validation error
- OSV.dev upstream unavailability causes timeout or error
- Very new CVEs not yet indexed in OSV.dev may be missing
- Package name format errors for Maven (requires group:artifact) cause lookup failure

## How this service works

Known vulnerabilities for one package version from OSV.dev, with CISA exploited-in-the-wild flag and the fixed version. Should I install this? Pass ?package=lodash&ecosystem=npm&version=4.17.15 (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Hex, Pub) and get every known advisory for that exact version from OSV.dev (GitHub, PyPA, Go and RustSec databases), whether any of them is on CISA's Known Exploited Vulnerabilities list, severity, and the version that fixes each.

## Output

A structured response listing every known OSV advisory for the specified package version, including CVE IDs, severity ratings, whether each advisory appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, and the minimum version that resolves each vulnerability.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method",
    "queryParams"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "package",
      "ecosystem",
      "version"
     ],
     "properties": {
      "package": {
       "type": "string",
       "maxLength": 214,
       "minLength": 1,
       "description": "Package name exactly as the registry has it (Maven: group:artifact)."
      },
      "version": {
       "type": "string",
       "maxLength": 64,
       "minLength": 1,
       "description": "The exact version to check."
      },
      "ecosystem": {
       "enum": [
        "npm",
        "PyPI",
        "Go",
        "crates.io",
        "Maven",
        "NuGet",
        "RubyGems",
        "Packagist",
        "Hex",
        "Pub"
       ],
       "type": "string",
       "description": "Package ecosystem."
      }
     }
    }
   }
  },
  "output": {
   "type": "object"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/apex-package-vulnerability-kev-checker-0bd6b531/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from apexfaucet.xyz](https://www.zero.xyz/host/apexfaucet.xyz/llms.txt)
