Skip to content
Moat or Bloat

Auditly

Dependency security scanner for GitHub repos that checks packages against CVE database

Web app Rated 7 Oct 2026Dormant

Bloat

130/500

Where it landed on the scale

Bloat
0
Float
300
Moat
400

Summary

Auditly is a working dependency scanner with OAuth sign-in for GitHub and GitLab, plus a one-click fix PR feature. It has no pricing, no payments, no privacy policy and no support contact. The idea is also well covered by free tools like Dependabot, so the reason to pay or switch is unclear, and activity stopped after June.

Bloat · Not much here works or looks likely to last, yet.

Breakdown

Five measures, 100 points each. Open the receipts under any of them to see the posts and pages behind the points.

Viability

Is there a real problem, someone who would pay, and a market this builder can actually reach?

The problem is real, but GitHub's own Dependabot and other free scanners already cover it. The site shows no pricing or payment path, so there's no believable way to charge yet, and it asks for repo-level access with no privacy policy or terms.

22/100

Rubric 21–40A real problem, but no plausible path to anyone paying, or a market well out of this builder's reach.

Receipts (3)
  1. Sign-in page requests repo / read_api scope for private access, with no pricing, payments, privacy policy or terms anywhere.

    Checked 7 Oct 2026 · auditly.kidus-yohannes.engineer (opens in a new tab)

  2. Pitches scanning every repo against a CVE database, which free built-in tools already do.

    “Launching a new product Auditly. Dependency security for your Github repos. Sign in with Github, It scans every repo you own, checks every package against CVE database, and tells you exactly what's vulnerable. Critical down to low. There is real time scan progress, CVE details per package, and Flags files that survive uninstall. works both on public and private repos. Please share with everyone t”

    Post · @kiduschronicless · 10 Jun 2026 · open on Telegram (opens in a new tab)

  3. Says users are adapting it, but gives no sign of anyone paying or committing to it.

    “Auditly is being adapted by users. This is really cool to see.”

    Post · @kiduschronicless · 17 Jun 2026 · open on Telegram (opens in a new tab)

Moat

What stops someone copying it?

It's a front end over the public OSV.dev database plus Git provider APIs, which someone could rebuild in a weekend or two. The Fix all PR feature is useful but not hard to copy, and there's no proprietary data or local-specific depth.

12/100

Rubric 0–20A thin wrapper or a clone that anyone here could rebuild in a weekend.

Receipts (2)
  1. The page credits vulnerability data to OSV.dev, so the core data isn't proprietary.

    Checked 7 Oct 2026 · auditly.kidus-yohannes.engineer (opens in a new tab)

  2. GitLab support and an auto-PR Fix all button are good features but are standard integration work.

    “just dropped some updates on Auditly 👇 - GitLab is now supported alongside GitHub - added a "Fix all" button that auto-creates a PR/MR fixing all vulnerable packages in one commit, with a commit link showing exactly what changed.”

    Post · @kiduschronicless · 22 Jun 2026 · open on Telegram (opens in a new tab)

Momentum

Did the updates keep coming?

It was worked on across about 12 days in June, with a launch and one feature update, then went quiet for 107 days.

0/100

  • Sustained shipping0/60

    Worked on across 12 days.

  • Consistency0/40

    Updates in 1 of 1 month.

  • Quiet

    No update for 107 days, so scaled to 48%.

Receipts (2)
  1. Earliest post about it.

    “Launching a new product Auditly. Dependency security for your Github repos. Sign in with Github, It scans every repo you own, checks every package against CVE database, and tells you exactly what's vulnerable. Critical down to low. There is real time scan progress, CVE details per package, and Flags files that survive uninstall. works both on public and private repos. Please share with everyone t”

    Post · @kiduschronicless · 10 Jun 2026 · open on Telegram (opens in a new tab)

  2. Most recent post about it.

    “just dropped some updates on Auditly 👇 - GitLab is now supported alongside GitHub - added a "Fix all" button that auto-creates a PR/MR fixing all vulnerable packages in one commit, with a commit link showing exactly what changed.”

    Post · @kiduschronicless · 22 Jun 2026 · open on Telegram (opens in a new tab)

Infrastructure

Does a real, working product exist?

A working product exists: a live site with GitHub and GitLab sign-in, scans, CVE details and an auto-fix PR, though it has no docs, status page or support contact.

66/100

  • It's live20/20

    https://auditly.kidus-yohannes.engineer/ responded when checked.

  • HTTPS5/5

    Served over HTTPS.

  • Real product25/35

    The product works: live site, OAuth sign-in for GitHub and GitLab, scanning and a fix-PR flow. It's still thin, since there are no docs and no visible pricing or account management beyond sign-in.

  • Own home10/10

    Lives on its own domain (auditly.kidus-yohannes.engineer).

  • Maintained0/15

    Last sign of shipping 2026-06-22.

  • Operations6/15

    There are accounts via OAuth and support for two Git platforms, but no docs, no status page, no public API and no support contact.

Receipts (5)
  1. https://auditly.kidus-yohannes.engineer/ responded when checked.

    Checked 7 Oct 2026 · auditly.kidus-yohannes.engineer (opens in a new tab)

  2. Live app with GitHub and GitLab sign-in and access scopes for private repos.

    Checked 7 Oct 2026 · auditly.kidus-yohannes.engineer (opens in a new tab)

  3. Describes real-time scan progress, per-package CVE details and severity levels.

    “Launching a new product Auditly. Dependency security for your Github repos. Sign in with Github, It scans every repo you own, checks every package against CVE database, and tells you exactly what's vulnerable. Critical down to low. There is real time scan progress, CVE details per package, and Flags files that survive uninstall. works both on public and private repos. Please share with everyone t”

    Post · @kiduschronicless · 10 Jun 2026 · open on Telegram (opens in a new tab)

  4. Reports a Fix all button that creates a PR/MR with a commit link.

    “just dropped some updates on Auditly 👇 - GitLab is now supported alongside GitHub - added a "Fix all" button that auto-creates a PR/MR fixing all vulnerable packages in one commit, with a commit link showing exactly what changed.”

    Post · @kiduschronicless · 22 Jun 2026 · open on Telegram (opens in a new tab)

  5. Accounts are present, while docs, status page and support are all false.

    Checked 7 Oct 2026 · auditly.kidus-yohannes.engineer (opens in a new tab)

Sustainability

Is it being set up to last?

It's distributed as a web app on its own domain, but there's no pricing, no payments, no privacy policy or terms, and it competes with free built-in tools, so its long-term footing is weak.

30/100

  • Distribution25/30

    A web app on its own domain.

  • Payments0/15

    No payment provider found.

  • Pricing0/10

    No pricing found on the site.

  • Revenue0/5

    No posts mention customers, prices or revenue, and the site has no payment provider.

  • Privacy policy0/7

    No privacy policy found.

  • Terms0/5

    No terms of service found.

  • Support0/8

    No support contact found.

  • Commitment5/20

    One builder shipped a launch and one meaningful update over twelve days, and listed it on a project directory. There's no roadmap, team, dedicated community, or activity since June 22.

Receipts (5)
  1. A web app on its own domain.

    Checked 7 Oct 2026 · auditly.kidus-yohannes.engineer (opens in a new tab)

  2. No payments detected and no pricing page.

    Checked 7 Oct 2026 · auditly.kidus-yohannes.engineer (opens in a new tab)

  3. A substantive update ships 12 days after launch.

    “just dropped some updates on Auditly 👇 - GitLab is now supported alongside GitHub - added a "Fix all" button that auto-creates a PR/MR fixing all vulnerable packages in one commit, with a commit link showing exactly what changed.”

    Post · @kiduschronicless · 22 Jun 2026 · open on Telegram (opens in a new tab)

  4. Listed on stark.et, a local project directory.

    “Auditly is live on stark.such a cool product btw @miheretabtrysstuff https://stark.et/project/auditly-51”

    Post · @kiduschronicless · 11 Jun 2026 · open on Telegram (opens in a new tab)

  5. Mentions plans to post on X, which is promotion rather than a project community.

    “I just posted Auditly on X, and i am thinking to post continuously there, i would love your guys support and follow me there https://x.com/KidusYoh/status/2064655153718776214”

    Post · @kiduschronicless · 10 Jun 2026 · open on Telegram (opens in a new tab)