Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-14257 brace-expansion through 5.0.7 is vulnerable to denial of service via m ...CVE-2026-14257 brace-expansion through 5.0.7 is vulnerable to denial of service via m ...CVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...GHSA-5c6j-r48x-rmvq Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()CVE-2026-34043 serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serializationCVE-2026-41907 uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentialityCVE-2025-30359 webpack-dev-server: webpack-dev-server information exposureCVE-2025-30360 webpack-dev-server: webpack-dev-server information exposureCVE-2026-14620 webpack-dev-server: webpack-dev-server: Arbitrary file opening and denial of service via exposed developer endpointsCVE-2026-14631 webpack-dev-server: webpack-dev-server: Denial of Service via malformed headersCVE-2026-6402 webpack-dev-server: webpack-dev-server: Information disclosure due to cross-origin source code exposureCVE-2026-9595 webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configurationCVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsCVE-2026-45736 ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`CVE-2026-12590 body-parser: body-parser: Denial of Service via invalid limit optionCVE-2025-68157 webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirectsCVE-2025-68458 webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behaviorYour dependencies cross-checked against the OSV vulnerability database.
GHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-848j-6mx2-7j84 Elliptic Uses a Cryptographic Primitive with a Risky ImplementationGHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-5c6j-r48x-rmvq Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()GHSA-qj8w-gfj5-8c6v Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objectsGHSA-w5hq-g745-h8pq uuid: Missing buffer bounds check in v3/v5/v6 when buf is providedGHSA-4v9v-hfq4-rm2v webpack-dev-server users' source code may be stolen when they access a malicious web siteGHSA-79cf-xcqc-c78w webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS originsGHSA-9jgg-88mc-972h webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browserGHSA-f5vj-f2hx-8m93 webpack-dev-server vulnerable to cross-site request forgery via internal developer endpointsGHSA-m28w-2pqf-7qgj webpack-dev-server vulnerable to denial of service via a malformed Host or Origin headerGHSA-mx8g-39q3-5c79 webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxiesGHSA-58qx-3vcg-4xpx ws: Uninitialized memory disclosureGHSA-96hv-2xvq-fx4p ws: Memory exhaustion DoS from tiny fragments and data chunksGHSA-v422-hmwv-36x6 body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementGHSA-38r7-794h-5758 webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistenceGHSA-8fgc-7cc6-rx7x webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behaviorCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.