Open-source. Offline. Deterministic.

You have hundreds of dependencies. Where does the license risk actually come from?

Most license tools list problems.

Codicense explains cause and impact.

$npm install -g codicense
$codicense init
$codicense scan

The Situation Every Developer Faces

$npm install some-package
# [3 months later]
Legal: "We can't ship this. License conflict."
You: "...which dependency?"

Your project has hundreds of dependencies.

Your scanner reports 23 conflicts.

The questions it won't answer:

Which dependency introduced the risk?

Most tools don't know. Codicense does.

What Makes Codicense Different

Codicense doesn't just scan dependencies. It traces cause, measures impact, and ranks fixes.

1.

Trace How Risk Enters

See exactly where a conflict originated and how it propagated.

2.

Understand Which Dependencies Matter Most

See which packages contribute the largest share of license risk.

3.

See How Changes Affect Risk

Compare options before making a decision.

Fits Into Real Workflows

Works in logs, PRs, audits, and screenshots.

Local Development

Find the root cause before it becomes a blocker.

Codicense shows where license risk enters your project and which dependency is responsible, while you are still coding.

$ codicense scan

23 conflicts found. 3 high priority.

CI/CD Pipeline

Prevent license regressions automatically.

Codicense fits cleanly into CI to stop new high-risk dependencies from being introduced without adding noise or dashboards.

$ codicense scan --fail-on critical,high

Only meaningful changes fail the build.

Pull Request Reviews

Explain risk clearly to reviewers and legal.

Codicense generates concise summaries that make license risk understandable in PRs without requiring context switching.

$ codicense scan --format summary

Reviewers see: what changed · why it matters · what fixes are available

Compliance Audits

Produce evidence without rework.

Codicense exports machine-readable SBOMs with license context for audits and supply chain requirements.

$ codicense scan --format sbom > sbom.json

No rescans. No manual reconstruction.

The same reasoning, wherever license risk shows up.

What Codicense Is (and Isn't)

What It Is

Shows cause and propagation

See where risk enters and how it spreads.

Provides evidence for decisions

Paths, context, and tradeoffs you can inspect.

Behaves like infrastructure

Local, deterministic, no accounts needed.

Supports judgment, not replaces it

Surfaces options. You decide.

What It Isn't

Not a cloud service

No accounts. No uploads. No lock-in.

Not a black box

Every result and score is inspectable.

Not a compliance gate

Information, not authority.

Not legal advice

Structure and evidence. Decisions are yours.

Compare: Other Tools vs. Codicense

FeatureOther ToolsCodicense
Detect conflicts
Show contamination path
Rank by causal impact
Suggest upgrade-first fixes
Explain license obligations
Works offline
Deterministic results
Free & open sourceSome

Get Started in 60 Seconds

# Install
$npm install -g codicense
# Set up your project
$codicense init
# Scan dependencies
$codicense scan
# Fix the biggest issue
$codicense scan --hotspots
$codicense fix <package-name>

That's it.

Open Source. Always Free.

Codicense is Apache-2.0 licensed.

No accounts·No uploads·No hidden behavior
Want to see how it works? Read the source code →

Install Now

npm install -g codicense