Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexityCVE-2026-14257 brace-expansion through 5.0.7 is vulnerable to denial of service via m ...CVE-2026-45149 brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric rangesCVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalizationCVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policiesCVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handlingCVE-2026-54290 hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardCVE-2026-44455 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionCVE-2026-44456 Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsCVE-2026-44457 Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageCVE-2026-44458 Hono has CSS Declaration Injection via Style Object Values in JSX SSRCVE-2026-47673 Hono: JWT middleware accepts any Authorization scheme, not only BearerCVE-2026-47674 Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 CVE-2026-47675 Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionCVE-2026-47676 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsCVE-2026-54286 hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-54287 hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeCVE-2026-54288 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`CVE-2026-54289 hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restCVE-2026-56761 hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSRCVE-2026-59895 Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityCVE-2026-59896 hono/jsx does not isolate context per request, leading to cross-request data disclosureCVE-2026-59897 Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2025-183 pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users mayPYSEC-2026-120 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array liPYSEC-2026-175 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registerPYSEC-2026-178 PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decodPYSEC-2026-179 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate PYSEC-2026-3004 pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streamsPYSEC-2026-3006 pypdf: Manipulated XMP metadata entity declarations can exhaust RAMPYSEC-2026-3007 pypdf: Possible long runtimes for wrong size values in incremental modePYSEC-2026-3009 pypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionPYSEC-2026-3010 pypdf: Inefficient decoding of FlateDecode PNG predictor streamsPYSEC-2026-3011 pypdf: Manipulated FlateDecode predictor parameters can exhaust RAMPYSEC-2026-3016 pypdf: Possible large memory usage for large offsets for layout mode textPYSEC-2026-3018 pypdf: Possible infinite loop when processing threads/articles in writerPYSEC-2026-3020 pypdf: Possible large memory usage for form XObjects during text extractionPYSEC-2026-3021 pypdf has long runtimes for wrong size values in cross-reference and object streamsPYSEC-2026-3022 pypdf: Possible infinite loop when processing outlines/bookmarks in writerPYSEC-2026-3025 pypdf: Manipulated XMP metadata streams can exhaust RAMPYSEC-2026-3026 pypdf: Manipulated FlateDecode image dimensions can exhaust RAMGHSA-55h5-xmcq-c37v pypdf: Possible long runtimes for repeated malformed cross-reference entries GHSA-5qjq-93h5-hrgp pypdf: Possible large memory usage for wrong image dimensionsGHSA-5xf7-4p34-54qr pypdf: Possible infinite loop for not terminated inline imagesGHSA-g867-7843-wf8q pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)GHSA-jm82-fx9c-mx94 pypdf: Missing stream length values ignore defined limitsPYSEC-2026-1851 Denial of service (DoS) via deformation `multipart/form-data` boundaryPYSEC-2026-1852 Python-Multipart has Arbitrary File Write via Non-Default ConfigurationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.