Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-35515 @nestjs/core: Nest: Server-Sent Events (SSE) injection and spoofing via unsanitized newline charactersCVE-2026-31808 file-type: file-type: Denial of Service due to infinite loop in ASF file parsingCVE-2026-32630 file-type: file-type: Denial of Service via excessive memory growth from crafted ZIP filesCVE-2026-2359 multer: Multer: Denial of Service via dropped file upload connectionsCVE-2026-3304 multer: Multer: Denial of Service via malformed requestsCVE-2026-3520 multer: Multer: Denial of Service via malformed requestsCVE-2026-5079 Multer vulnerable to Denial of Service via deeply nested field namesCVE-2026-5038 Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploadsCVE-2026-8723 ### Summary `qs.stringify` throws `TypeError` when called with `arr ...CVE-2026-12590 body-parser: body-parser: Denial of Service via invalid limit optionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-36xv-jgw5-4q75 @nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')GHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-5v7r-6r5c-r473 file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-headerGHSA-j47w-4g3g-c36v file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entryGHSA-5j98-mcp5-4vw2 glob CLI: Command injection via -c/--cmd executes matches with shell:trueGHSA-3p4h-7m6x-2hcm Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploadsGHSA-5528-5vmv-3xc2 Multer Vulnerable to Denial of Service via Uncontrolled RecursionGHSA-72gw-mp4g-v24j Multer vulnerable to Denial of Service via deeply nested field namesGHSA-v52c-386h-88mc Multer vulnerable to Denial of Service via resource exhaustionGHSA-xf7r-hgr6-v32p Multer vulnerable to Denial of Service via incomplete cleanupGHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob MatchingGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-q8mj-m7cp-5q26 qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is setGHSA-ph9p-34f9-6g65 tmp has Path Traversal via unsanitized prefix/postfix that enables directory escapeGHSA-v422-hmwv-36x6 body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementGHSA-52f5-9888-hmc6 tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameterGHSA-38r7-794h-5758 webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistenceGHSA-8fgc-7cc6-rx7x webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behaviorCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.