Every modern web application is based on a multitude of freely available software fragments, so-called open source packages. Since these are maintained by a public community, checking the packages for suitability for integration into enterprise software is essential to ensure the security of the overall solution.