Excalion

SupplyChainGuard

Know every script running on your site. And who put it there.

What is SupplyChainGuard?

Every website loads third-party scripts. CDNs, analytics, tag managers, payment SDKs - dozens of external dependencies running code on your pages. One compromised library and your users are exfiltrated. SupplyChainGuard inventories every script on any page, identifies library versions, checks for known CVEs, and detects when a script’s hash changes between visits - the exact signal that flagged the Polyfill.io supply chain attack.

Features

  • JS library inventory - Detects every third-party script loaded on the page with library name, version, and CDN source.
  • CVE verification - Cross-references detected library versions against known vulnerability databases in real time.
  • SRI hash verification - Checks whether Subresource Integrity hashes are present and valid for each external script.
  • Hash mutation detection - Tracks script hashes between visits. If a CDN-hosted file changes content silently, you know immediately.
  • CDN reputation analysis - Flags scripts loaded from deprecated, hijacked, or low-reputation CDN domains.
  • CSP audit - Analyzes the page’s Content-Security-Policy script-src directive and highlights overly permissive rules.
  • Free scan, paid monitoring - Scan any page instantly for free. Paid tier adds continuous perimeter monitoring and alerting.

Who is it for?

Built for DevSecOps engineers, AppSec teams, and anyone responsible for what runs in production browsers. If you audit third-party risk, manage CSP policies, or respond to supply chain incidents - this is your first line of visibility.