License Detector

License Detector

A CLI that reads the actual license text of your dependencies — not just declared metadata — across 21+ package ecosystems including npm, pip, Maven, Go, and Cargo, entirely offline.

🔗 Visit License Detector
📁 Security & Privacy🗣️ English📅 August 31, 2026

Description

A package's declared license in package.json or setup.py isn't always the real story — licenses get modified, dual-licensed, or misdeclared, and metadata-only scanners miss all of that. License Detector actually reads the license text itself to figure out what's really there.

License Detector resolves lockfiles across 21+ package ecosystems (npm, pip, Maven, Go modules, Cargo, Ruby, .NET, and more), works fully offline using an embedded license corpus, and flags modified licenses, dual/OR licensing, and other gaps that metadata-only tools miss. It outputs in text, JSON, CSV, or SBOM (SPDX/CycloneDX) formats, supports SARIF for CI integration, lets you define custom compliance policies, and can gate a build via exit codes. It also does deeper asset scanning for media rights and AI-generation provenance (C2PA credentials). The CLI itself is free and open source under the Elastic License 2.0; a hosted GitHub App at licensedetector.com adds PR checks and a dashboard as a separate, proprietary offering.

💬 Our review

The short version: License Detector's core differentiator — actually reading license text instead of trusting declared metadata — is a legitimate advantage over most open-source license scanners, and the free CLI alone is enough for most individual developers or small teams.

FOSSA and Black Duck are the established enterprise-grade options, with mature dashboards, legal-team workflows, and broad ecosystem coverage, but they're commercial products with enterprise pricing to match. ScanCode Toolkit is the closest free/open-source peer in spirit — it also does deep license-text analysis rather than metadata lookup — so the two are worth comparing directly if you want a fully offline, free option; License Detector's edge is its explicit 21+ ecosystem lockfile resolution and CI-ready SARIF/exit-code gating out of the box. If your team needs dashboards and PR-level checks without setting up your own CI wiring, the hosted GitHub App is the natural upsell, but the CLI alone covers real compliance-scanning needs for free.

💰 Pricing

FreemiumCLI gratuite (Elastic License 2.0) ; app GitHub hébergée payante en option
CLI (Open Source) GratuitHosted GitHub App Payant (montant non précisé)

📊 Global score

53Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile90/100Excellent

Profile completeness

🤖 AI-enriched data

💰 Pricing model
🆓 Freemium

CLI gratuite et open source (Elastic License 2.0) ; app GitHub hébergée payante (licensedetector.com) pour dashboard et checks PR

👥 Target audienceDéveloppeurs, équipes DevOps, équipes conformité, entreprises gérant des dépendances open source
🗣️ Languagesen
🌍 Target countriesMarché anglophone, développeurs internationaux
👍

Pros

Analyse le texte réel des licences, pas seulement les métadonnées déclarées

21+ écosystèmes de paquets supportés (npm, pip, Maven, Go, Cargo...)

Fonctionne entièrement hors ligne

Formats de sortie multiples (JSON, CSV, SBOM, SARIF) pour intégration CI

👎

Cons

Dashboard et checks PR réservés à l'offre payante hébergée

Moins de maturité que FOSSA ou Black Duck en entreprise

Tarification de l'app hébergée non précisée

❓ Frequently asked questions

What is License Detector in one sentence?
How much does it cost?
Which package ecosystems does it support?
Does it need an internet connection?
Is it worth it compared to alternatives?
Which tool should you pick for your case?