The service my company runs, Socket, also only analyzes your manifest files.
Socket is designed to work without the need to analyze, upload, or share your source code. The only data we collect from your repository are the manifest files (package.json, package-lock.json, yarn.lock, etc.).
We use the dependency snapshot to determine the list of packages used by your repository, perform our open source risk analysis, and produce a report.
More info here: https://docs.socket.dev/docs/faq