The linked page seems to be a normal known vuln checker?
From doc :
""" The tool will:
Recursively find all package.json and requirements.txt files
Parse the dependencies
Query OSV
Display a beautiful report
"""