Skip to main content
AIDiveForge AIDiveForge

Tmppr vs VulnFeed

Tmppr and VulnFeed are both coding assistants tracked by AIDiveForge. Below is a side-by-side comparison of pricing, capabilities, platforms, and ownership — sourced from each tool's live website and verified before publishing.

Tmppr

Tmppr

The core workflow is a full pull-request lifecycle that runs on localhost: agents open PRs, trigger CI via your existing GitHub Actions YAML, review each other's diffs inline, and ship only after merge gates clear. An MCP server registers every action as a native tool for Claude Code and Codex, so agents call PR open, review, and merge without glue code. The stacked-PR workflow handles dependent branches in order without manual rebasing. The ceiling appears when teams need shared CI infrastructure — local runners work for solo or small-team setups, but shared minutes require the paid cloud runner option. No API means external systems cannot push events into tmppr without building through the plugin SDK.

VulnFeed

VulnFeed

VulnFeed is an MCP server that reads your lockfile directly, cross-references NVD and GitHub Advisories against only the packages you ship, and surfaces results ranked by EPSS — the exploit probability score that separates CVEs attackers are actually using from the ones sitting dormant for years. It runs locally via a single uvx command and feeds results into Claude Code, Cursor, VS Code, or Windsurf. The free tier caps at 10 scans per day and one monitored project; teams that scan frequently or monitor multiple repos will hit that ceiling fast. At that point, the choice is a paid upgrade or a full migration to something like Snyk, which adds code-level remediation context VulnFeed does not provide.

AttributeTmpprVulnFeed
PricingPaidPaid
Price$14/mo
Free trialNoNo
Open sourceNoNo
Has APINoYes
Self-hosted optionYesYes
PlatformsmacOS, Linux, WindowsClaude Code, Claude Desktop, Cursor, VS Code, Windsurf
Pros
  • MCP server auto-registered on init, so Claude Code and Codex agents call PR, CI, review, and merge as native tools — no glue scripts to maintain between your agent loop and the forge.
  • Executes existing GitHub Actions YAML locally with live log streaming, which means you reuse CI definitions you already have instead of rewriting them for a new platform.
  • Strict 127.0.0.1 binding with no telemetry and no account required for local use, so teams with hard code-leakage policies can run full agent loops without sending source off the machine.
  • Full-lifecycle event triggers covering the entire issue-to-merge cycle, which means a failed CI run automatically queues a fix agent rather than leaving the loop waiting for a human to notice.
  • Plugin SDK lets you add agent providers, merge rules, and automation triggers from a single installable package without forking core, so your customizations survive upstream updates.
  • Reads your actual lockfile rather than scanning the full language ecosystem, which means you see only CVEs that affect packages you ship — not hundreds of irrelevant hits from packages you never installed.
  • EPSS scoring surfaces CVEs by real-world exploit probability alongside severity, so you patch the vulnerability attackers are using instead of the one with the highest CVSS number that has sat unexercised for three years.
  • Returns the exact upgrade version per package rather than stopping at 'you are vulnerable,' which means the fix is actionable inside the same conversation with your AI client.
  • Continuous monitoring indexes new CVEs shortly after publication, so a vulnerability disclosed overnight appears in results at your next morning session rather than at your next scheduled scan.
  • Flat-rate paid tier is not per-seat or per-repo, which means a team adding a second developer or a third project does not trigger a pricing jump.
Cons
  • Local CI runners work for a single machine — the moment a team needs shared CI minutes, parallel runners, or a bigger build box, they hit a wall that only the paid cloud runner option unblocks. Teams evaluating cost at that point compare against existing cloud CI they already pay for.
  • No public API means external systems — monitoring tools, issue trackers, deployment pipelines — cannot push events into tmppr without a plugin authored against the SDK. Teams that need bidirectional integration with an existing platform end up maintaining a custom plugin as a second system.
  • The tool has no listed alternatives in market, but teams whose agent workflows already live inside a hosted platform like GitHub Actions with Copilot or a managed agent orchestration service will find tmppr's local-first model an architectural mismatch rather than a drop-in addition — those teams do not adopt it, they replace it.
  • The free tier caps at 10 scans per day and one monitored project — a developer running scans across multiple services or triggering scans on file save will exhaust the daily quota before noon, at which point scanning stops until the counter resets.
  • VulnFeed identifies vulnerable versions and recommends upgrade targets but provides no code-level remediation: no PR generation, no inline diff, no analysis of whether your specific call path reaches the vulnerable function. Teams that need that layer move to Snyk or Socket, both of which offer it — at significantly higher per-developer cost.
  • The tool set covers scanning, CVE lookup, monitoring, and alerts, but there is no policy enforcement layer. Teams that need to fail a build when a CRITICAL CVE with high EPSS is introduced have to wire that logic themselves outside VulnFeed.
Bottom line

Only VulnFeed exposes a public API. Choose based on which difference matters most for your workflow.

Frequently asked questions

What is the difference between Tmppr and VulnFeed?

Tmppr is Paid, while VulnFeed is Paid. Compare pricing, free trial, API, platforms, and pros/cons in the table above on AIDiveForge.

Is Tmppr better than VulnFeed?

It depends on your workflow. Use the side-by-side attributes (pricing, open source, API, self-hosted, platforms) to decide. AIDiveForge does not rank a universal winner — we publish verified facts so you can choose.

Tmppr vs VulnFeed: which should I pick?

Pick Tmppr if its pricing model, openness, or platform fit matches your constraints; pick VulnFeed otherwise. Check free-trial availability on each listing if you want to test before committing.

Comparison data is sourced and verified by the AIDiveForge data pipeline. AIDiveForge is editorially independent.