SCAN
Scan endpoints for packages & browser extensions















PexLens scans software packages installed on endpoints as well as packages present within project folders. It also identifies browser and developer extensions, giving organizations visibility into the software components running across their environment.
PexLens currently analyzes major open-source package ecosystems, including npm, PyPI, MavenCentral, RubyCentral.org with support for additional ecosystems evolving as the platform expands.
Package installation requests can be routed through the PexLens Proxy, where the package is evaluated against PexLens intelligence and your organization’s security policies. Packages that fail the defined security criteria can be blocked before installation.
Yes. Organizations can define their own security requirements, including risk and CVE thresholds, and PexLens applies those policies when evaluating package requests.
Yes. PexLens can identify and assess browser extensions and developer-environment extensions, including VS Code extensions, helping organizations detect malicious, suspicious, or risky extensions.
PexLens continuously discovers and analyzes new packages and package versions, updating its intelligence as the software ecosystem evolves. This helps organizations make decisions using current risk information rather than relying only on historical scans.