# PkgTrace > PkgTrace grades the maintenance health and known vulnerabilities of open-source dependencies from A to F, explains each grade in plain language, and suggests healthier alternatives. ## What it does - Scans a GitHub repository, a single package (npm, Packagist, PyPI, RubyGems) or a dependency manifest (package.json, composer.json, requirements.txt, Gemfile, go.mod, pom.xml, build.gradle). - Scores issue responsiveness, resolution rate, backlog health and risk flags (commit and release activity, contributor concentration) from live GitHub data. - Lists known vulnerabilities with affected and fixed versions. - Tracks repositories in team portfolios with scheduled rescans and grade-drop alerts. ## Pages - [Home and scanner](https://staging.pkgtrace.com) - [Scan a dependency file](https://staging.pkgtrace.com/upload) - [Create an account](https://staging.pkgtrace.com/register) - [Privacy Policy](https://staging.pkgtrace.com/privacy) - [Terms of Service](https://staging.pkgtrace.com/terms)