Know What You're Buying Before Your Exclusivity Window Closes.
DiligencePack audits a target GitHub repository for copyleft license exposure in its declared dependencies, contributor concentration (bus factor), credential patterns in the current source tree, and test infrastructure — then turns the findings into an executive memo with a deal negotiation matrix in dollars.
Self-hosted uptime monitoring platform (hypothetical acquisition)
Analyzed public repository louislam/uptime-kuma • 780 files scanned • Risk Score: 73/100 (HIGH)
The figures below come from the sample analysis of louislam/uptime-kuma, framed as a hypothetical acquisition — see the full report for the framing and methodology.
1 copyleft dependency found
Among the direct dependencies declared in the target's manifest, classified for commercial-redistribution risk.
Bus factor: 16
The primary contributor authored 51.8% of all-time commits.
46 test files / 563 source files
A 8% test-to-source file ratio, scored for post-acquisition regression risk.
Start Technical Due Diligence
Enter the target repository below. Repository files are fetched only to run the analysis and are not stored.
What DiligencePack Inspects
Built for software acquisitions, micro-PE buyers, and M&A diligence teams.
Open-Source License Exposure
Classifies the license of every direct dependency declared in the target's package.json — copyleft (AGPL, GPL, SSPL), weak copyleft, permissive, or unlicensed — and flags copyleft exposure that needs commercial review before close.
Key-Person & Bus Factor
Measures contributor concentration from all-time GitHub commit counts to show whether codebase knowledge depends on a single author — and whether a transition escrow is warranted.
Secret & Credential Patterns
Scans a risk-prioritized subset of files in the current default branch for credential patterns — payment-provider keys, cloud access keys, access tokens, private keys — that require rotation before close.
Deal Negotiation Matrix
Translates the findings into concrete dollar price adjustments, transition escrow holdbacks, and conditions precedent for deal closing.
Frequently Asked Questions
How is our source code kept private and secure?
Repository file contents are fetched transiently to run the analysis and are not stored. The finished report retains only findings — file paths, dependency names, and contributor handles. Nothing you submit is used to train models. Access tokens are used once for the analysis and never stored.
What repositories are supported?
DiligencePack analyzes GitHub repositories — public, or private with a read-only access token. License classification covers the direct dependencies declared in package.json, so it is most complete for JavaScript/TypeScript projects. The contributor-concentration, secret-pattern, and test-infrastructure checks apply to any GitHub repository.
What is the refund policy?
If DiligencePack fails to generate your technical due diligence report within 24 hours of payment due to a system failure, contact support for a full refund. Verifiable non-use within 30 days is also eligible for a full refund.