Sonatype Nexus IQ Evaluation

Sonatype Nexus IQ Evaluation - Scan Open Source Repositories for known Vulnerabilities.
What is Sonatype Nexus IQ Evaluation?
Sonatype Nexus IQ Evaluation is a Chrome extension allowing users to inspect open source packages for security vulnerabilities before downloading them. It is designed to integrate with a valid Sonatype Nexus Lifecycle instance, allowing for detailed package analysis. The plugin supports multiple package managers across diverse platforms, enabling broad-spectrum inspection of risky open source repositories.

Extension stats

Users: 937 ▲ 12
Rating: 5.00 (4)
Version: 1.10.0 (Last updated: 2023-07-14)
Creation date: 2020-05-27
Risk impact: High risk impact
Risk likelihood: Low risk likelihood
Manifest version: 2
Permissions:
  • activeTab
  • declarativeContent
  • cookies
  • background
  • storage
  • https://pkgs.alpinelinux.org/
  • https://anaconda.org/anaconda/
  • https://community.chocolatey.org/
  • https://clojars.org/
  • https://cocoapods.org/
  • See more
Size: 2.40M

Other platforms

Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions? Install Chrome-Stats extension to view Chrome-Stats data as you browse the Chrome Web Store.
Chrome-Stats extension

Extension summary

This Chrome Extension works with Sonatype Nexus Lifecycle to inspect an OSS package before you download it. The plugin requires a valid Sonatype Nexus Lifecycle instance. You will be prompted to connect to your Sonatype Nexus IQ Server during setup. Note: Supported by Sonatype.

The extension works with the following package managers and their websites.

  1. .Net – NuGet – https://www.nuget.org/
  2. Alpine – Linux – https://pkgs.alpinelinux.org/
  3. Chocolatey – Windows – https://community.chocolatey.org/
  4. Clojars – Clojure – https://clojars.org/
  5. CocoaPods – iOS – https://cocoapods.org/
  6. Conan – C/C++ – https://conan.io/center/
  7. Conda – Python – https://anaconda.org/anaconda/
  8. Debian – Linux – https://packages.debian.org/
  9. Debian – Linux – https://tracker.debian.org/pkg/
  10. GitHub – releases – https://github.com/*/releases/tag/*
  11. Golang – Go – https://pkg.go.dev/
See more

User reviews

A great tool for analyzing OSS components on the web for high-risk security vulnerabilities prior to downloading for use. Prevent mistakes early on in the SDLC by alerting on insecure packages before they are built in to application code.
by Neil Schloth, 2020-07-22
View all user reviews

Extension safety

Risk impact

Sonatype Nexus IQ Evaluation is risky to use as it requires a number of sensitive permissions that can potentially harm your browser and steal your data. Exercise caution when installing this extension. Review carefully before installing. We recommend that you only install Sonatype Nexus IQ Evaluation if you trust the publisher.

Risk likelihood

Sonatype Nexus IQ Evaluation has earned a fairly good reputation and likely can be trusted.

Upgrade to see risk analysis details

Promo images

Sonatype Nexus IQ Evaluation small promo image
Small promo image

Similar extensions

Here are some Chrome extensions that are similar to Sonatype Nexus IQ Evaluation: