---
title: "lopper"
pageType: "tool-profile"
schemaVersion: "1.0"
snapshotId: "tv-20260915-f4c107995a2e"
generatedAt: "2026-09-15T07:02:20.000Z"
canonicalUrl: "https://toolvitals.com/tools/lopper/"
jsonUrl: "https://toolvitals.com/api/agent/tools/lopper"
indexable: true
---

# lopper

measure dependency waste and attack surface before it ships

## Decision context

- Status: active
- ToolVitals score: 93/100
- Health score: 93/100
- Shipping score: 95/100
- Score mode: verdict
- Data confidence: 90/100
- Source coverage: 85/100
- Last evidence check: 2026-09-14

## Classification

- Use case: Security Scanning (security-scanning)
- Category: Security & Compliance (security)
- Tool mode: Source-visible project
- Openness: OSI-approved OSS
- License: MIT
- Tags: open-source, cli, dependency-analysis, developer-tools, go, golang, static-analysis, supply-chain-security, terminal-ui, attack-surface

## Public repository signals

- Repository: [ben-ranford/lopper](https://github.com/ben-ranford/lopper)
- Stars: 2 (adoption context only)
- Forks: 0
- Open issues: 152
- Last commit date: 2026-09-14
- Releases in 90 days: 30

## Source receipts

- [Official website](https://ranford.dev/) — checked 2026-09-14
- [Source repository](https://github.com/ben-ranford/lopper) — checked 2026-09-14

## Discovery status

- Search indexable: yes
- Reason: sufficient tool evidence

## Interpretation limits

- ToolVitals scores summarize bounded public maintenance, shipping, openness, and evidence signals. They are not user-review ratings.
- GitHub stars and related popularity metrics are adoption context, not quality evidence.
- Missing values mean not collected or not confidently established; they do not mean zero.
- Public signals do not prove security, uptime, support quality, customer satisfaction, or production suitability.
- Verify material decisions against the linked first-party sources and your own requirements.
