Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexityCVE-2026-14257 brace-expansion through 5.0.7 is vulnerable to denial of service via m ...CVE-2026-45149 brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric rangesCVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalizationCVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policiesCVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handlingCVE-2026-54290 hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardCVE-2026-44455 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionCVE-2026-44456 Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsCVE-2026-44457 Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageCVE-2026-44458 Hono has CSS Declaration Injection via Style Object Values in JSX SSRCVE-2026-47673 Hono: JWT middleware accepts any Authorization scheme, not only BearerCVE-2026-47674 Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 CVE-2026-47675 Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionCVE-2026-47676 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsCVE-2026-54286 hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-54287 hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeCVE-2026-54288 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`CVE-2026-54289 hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restCVE-2026-59895 Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityCVE-2026-59896 hono/jsx does not isolate context per request, leading to cross-request data disclosureCVE-2026-59897 Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationCVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted inputYour dependencies cross-checked against the OSV vulnerability database.
GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-jxxr-4gwj-5jf2 brace-expansion: Large numeric range defeats documented `max` DoS protectionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-4c8g-83qw-93j6 fast-uri vulnerable to host confusion via failed IDN canonicalizationGHSA-q3j6-qgpj-74h6 fast-uri vulnerable to path traversal via percent-encoded dot segmentsGHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-v39h-62p7-jpjc fast-uri vulnerable to host confusion via percent-encoded authority delimitersGHSA-2gcr-mfcq-wcc3 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsGHSA-3hrh-pfw6-9m5x Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionGHSA-69xw-7hcm-h432 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionGHSA-88fw-hqm2-52qc hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardGHSA-9vqf-7f2p-gf9v Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsGHSA-f577-qrjj-4474 Hono: JWT middleware accepts any Authorization scheme, not only BearerGHSA-hvrm-45r6-mjfj hono/jsx does not isolate context per request, leading to cross-request data disclosureGHSA-j6c9-x7qj-28xf hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeGHSA-p77w-8qqv-26rm Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageGHSA-qp7p-654g-cw7p Hono has CSS Declaration Injection via Style Object Values in JSX SSRGHSA-rv63-4mwf-qqc2 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`GHSA-w62v-xxxg-mg59 Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityGHSA-wgpf-jwqj-8h8p hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restGHSA-wwfh-h76j-fc44 hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-xgm2-5f3f-mvvc Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationGHSA-xrhx-7g5j-rcj5 Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-npm-install-script npm-install-script match in canvas 3.2.3A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.