The idea is to create a plugin which resolve the dependencies of an extension and for each one, check if there is any known vulnerability.