Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2019-17495 Cross-site scripting in Swagger-UICVE-2019-17495 Cross-site scripting in Swagger-UICVE-2019-17495 Cross-site scripting in Swagger-UICVE-2019-17495 Cross-site scripting in Swagger-UICVE-2019-17495 Cross-site scripting in Swagger-UICVE-2019-17495 Cross-site scripting in Swagger-UICVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2023-2976 guava: insecure temporary directory creationCVE-2023-2976 guava: insecure temporary directory creationCVE-2023-2976 guava: insecure temporary directory creationCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissionsCVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissionsCVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissionsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methodsGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methodsGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methodsGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methodsGHSA-c427-hjc3-wrfw Cross-site scripting in Swagger-UIGHSA-5j33-cvvr-w245 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityGHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly appliedGHSA-83qj-6fr2-vhqg Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTGHSA-fpj8-gq4v-p354 Apache Tomcat - Client certificate verification bypassGHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown userGHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validatedGHSA-vfww-5hm6-hx2j Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control SequencesGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methodsGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-c427-hjc3-wrfw Cross-site scripting in Swagger-UICode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 2.4/10scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Code-Review Code-Review scored 0: Found 0/30 approved changesets -- score normalized to 0scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0scorecard-SAST SAST scored 0: no SAST tool detectedscorecard-Security-Policy Security-Policy scored 0: security policy file not detected