Your AI assistant writes code against outdated APIs, and your dependencies age quietly until an upgrade becomes a quarter-long project. Vibgrate measures both problems before they bite.
Vibgrate CLI scans your manifests — never your source — and keeps two scores deliberately separate: DriftScore (0–100, how far behind your stack is) and RiskScore (whether any of it is exposed right now). A current stack with one actively exploited CVE and a three-majors-behind stack with no known exploit need different responses; one number can't tell you which you have.
It covers 19 ecosystems including legacy estates, runs offline, and needs no signup. The scoring method is published — every factor, source, and formula — with a citable DOI.
Also in the box: Vibgrate AI Context (vg serve), a local-first MCP server that gives your AI assistant version-correct library docs plus a code map plus offline drift, matched to your lockfile. And DriftScore badges for your README.
Free to try: npx @vibgrate/cli scan — results in about a minute. Team features on Vibgrate Cloud.