# LowEndInsight

> Open source supply chain risk analysis for any public git repository: contributor concentration, commit currency, large recent commits, SBOM risk, and how much of a project is written by agents. Agents pay per use over the Machine Payments Protocol (MPP), with no account.

Operated by (r)evolve (https://revolveteam.com). Source: https://github.com/kitplummer/lowendinsight

**Payments are in test mode.** Stablecoin payments use pathUSD on Tempo testnet, and no real money moves.

## Analyze a repository without an account

1. `POST https://lowendinsight.dev/v1/analyze` with body `{"urls": ["https://github.com/owner/repo"]}` and no credentials.
2. The response is `402 Payment Required` with a `WWW-Authenticate: Payment` challenge (MPP): method `tempo`, intent `charge`, and a request naming the amount, token, recipient address, chain id and memo.
3. Transfer exactly that amount, with that memo, to that address, from the wallet that signs the transaction. Retry the same request with `Authorization: Payment <credential>` carrying the transaction hash. An MPP client such as `mppx` does this for you.
4. The response is `200` with the analysis, a `Payment-Receipt` header, and a `Lei-Api-Key` header.
5. Keep the key. Send `Authorization: Bearer <key>` on later requests to spend the balance without paying again. The key is shown once.

Other paid routes, same flow: `POST /v1/analyze/sbom` (a CycloneDX or SPDX SBOM; priced per repository it names) and `POST /v1/analyze/batch` (dependencies). `GET /v1/analyze/{uuid}` fetches a job's result. Full schema: https://lowendinsight.dev/openapi.json

Send `/v1/analyze/batch` the complete resolved dependency set, not a subset. Anything derived from the shape of the set -- how packages relate, which were chosen rather than inherited -- assumes the whole tree, and a partial list is wrong silently: nothing in the response marks it. Per-package risk is unaffected.

Batch responses carry `ranking`, worst first, so you need not read every entry. `rank` compares only within one response. It is `null` for anything not yet analysed, which is not zero -- zero is a clean repository, null is one nobody has looked at yet.

A request is priced before it runs, from which repositories already have cached reports. It is charged when accepted, whether it completes in the request or runs asynchronously. A balance smaller than the request is asked to top up by at least the difference.

## Reading a report

Two currency figures, and they disagree on one package in twenty-three.

`commit_currency` is the time since the last commit -- the signal everyone has.
`functional_commit_currency` is the time since the last commit that changed
behaviour, excluding bot authors and documentation- or metadata-only changes. A
dependency bump refreshes the first and not the second.

Measured across 461 of the most-depended-upon packages in npm, PyPI, Go,
Packagist and RubyGems: **20 had a commit inside a year and no functional commit
for over a year, and 17 of those 20 carry no known vulnerability.** For those,
neither a last-commit check nor a CVE scan reports anything.
`github.com/pkg/errors` read as 27 weeks and had not had a functional commit in
302.

So prefer `functional_commit_currency` when deciding whether a project is still
maintained. The measurement, the twenty packages and its limits:
https://github.com/kitplummer/lowendinsight/blob/main/docs/findings/2026-10-05-one-in-twenty-three.md

Project size is the stronger predictor of staleness in those data: packages with
five or fewer contributors were stale three-quarters of the time, those with
five hundred or more one time in twenty. `functional_contributors` is in every
report.

## Pricing

**LowEndInsight is in beta and analysis is free.** No credits are spent for an
analysis, no usage is billed, and accounts are limited to
200 analyses a
month -- the allowance, not a price, is what bounds the beta.

**If you have no account you will still be asked for
500 credits
($0.50) once.** That is the smallest amount these payment
rails will settle, and during beta it buys an account rather than analysis: the
credits are not spent while analysis is free, and they remain yours to spend when
it is not. An account costs nothing to create, so without this every allowance
would be an allowance per attacker.

The rates below are what will apply when beta ends. They are published now so
nothing changes silently later; today they are not charged.

- One credit is $0.001.
- A repository with a cached report: 5 credits ($0.005).
- A repository analyzed fresh: 50 credits ($0.05).
- An agent buys a block of 15,000 credits ($15.00) when its balance runs out. During beta the first challenge is 500 credits ($0.50) instead, and nothing is spent from it.

## Ways to pay

- **Stablecoin, MPP `tempo`** (available): any agent, no account. pathUSD on Tempo testnet, verified and settled by Stripe.
- **Card through an agent wallet, MPP `stripe`** (available): agents that already have an API key. A Shared Payment Token from an agent wallet such as Link. Not offered without an account: a card token identifies no one to hold the balance.
- **Free tier**: people who sign up at https://lowendinsight.dev/signup, 200 analyses a month. During beta this allowance applies to every account, paid or not, and nothing is charged beyond it -- requests above it are refused rather than billed.
- **Pro**: people, through Stripe Checkout at signup. $29/month, including $15.00 of usage.

## No account, and why

- An agent has no signup, email or organization to give. The payment is the identity: the wallet that paid holds the balance.
- **Kept:** money and counts. Purchases and debits are recorded with the paying wallet and amount, the financial record of what was paid and spent. Monthly analysis counts are also kept.
- **Not kept:** which repositories a wallet analyzed. They aren't recorded against the payer, and routine production logs don't name them.
- Reports are cached by repository, not by who asked, so a cached report is cheaper for everyone.
- No free allowance for wallets: a wallet costs nothing to create, so a free allowance per wallet would be a free allowance per attacker.
- A stablecoin transfer is public on the Tempo testnet chain, as every on-chain payment is. What it paid for is not.
