Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2026-43966 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Reque ...CVE-2022-42975 Phoenix before 1.6.14 mishandles check_origin wildcardingCVE-2021-46871 phoenix_html allows Cross-site Scripting in HEEx class attributesGHSA-j3gg-r6gp-95q2 XSS in HEEx class attributesCVE-2026-8468 Plug: Unbounded buffer accumulation in multipart header parsing causes denial of serviceYour dependencies cross-checked against the OSV vulnerability database.
GHSA-w4f7-4cxr-rv3c cowboy and gun affected by an HTTP Request/Response Splitting vulnerabilityEEF-CVE-2026-43970 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY FrameEEF-CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoSEEF-CVE-2026-32686 Unbounded exponent in decimal enables unauthenticated DoSEEF-CVE-2026-56811 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of serviceEEF-CVE-2026-56812 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiffGHSA-p8f7-22gq-m7j9 Phoenix before 1.6.14 mishandles check_origin wildcardingGHSA-5g2h-9x5v-5h3x phoenix_html allows Cross-site Scripting in HEEx class attributesEEF-CVE-2026-56814 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)EEF-CVE-2026-8468 Unbounded buffer accumulation in multipart header parsing causes denial of service in plugEEF-CVE-2026-56813 Cookie attribute injection in Plug.Conn.Cookies.encode/2GHSA-j3gg-r6gp-95q2 XSS in HEEx class attributesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.