Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
RUSTSEC-2023-0071 Marvin Attack: potential key recovery through timing sidechannelsRUSTSEC-2026-0188 WASI hard links and renames bypass wasmtime-wasi's FilePerms for destinationGHSA-3qhv-2rgh-x77r pnpm: Repository config can expand victim environment secrets into registry requests before scripts runGHSA-4gxm-v5v7-fqc4 pnpm: Reserved bin name deletes PNPM_HOME during global removeGHSA-5wx6-mg75-v57r pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycleGHSA-72r4-9c5j-mj57 pnpm: `patch-remove` could delete project-selected files outside the patches directoryGHSA-fr4h-3cph-29xv pnpm: Hoisted install imports lockfile alias outside node_modulesGHSA-gj8w-mvpf-x27x pnpm: Repository-controlled configDependencies can select a pacquet native install engineGHSA-qrv3-253h-g69c pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configGHSA-v23m-ccfg-pq9h pnpm: `stage download` writes outside its destination directory via manifest name/version traversalGHSA-w466-c33r-3gjp pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesRUSTSEC-2026-0222 Stores can mix up type indices between enginesRUSTSEC-2026-0182 Leak in WASIp1 `fd_renumber` implementationRUSTSEC-2026-0190 Unsoundness in `Error::downcast_mut()`RUSTSEC-2026-0204 Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalidRUSTSEC-2026-0221 `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`RUSTSEC-2024-0384 `instant` is unmaintainedCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.