Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-5458-7hh9-v7p4 pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names GHSA-4gc7-5j7h-4qph Spring Framework DataBinder Case Sensitive Match ExceptionGHSA-jmp9-x22r-554x Spring Framework annotation detection mechanism may result in improper authorizationGHSA-775g-4xr8-78h8 Spring Framework Denial of Service via Integer Overflow in SpEL ExpressionsGHSA-9cmq-m9j5-mvww Spring Framework vulnerable to Denial of ServiceGHSA-r5w3-xv2f-j59q Spring Framework Algorithmic Denial of Service via SpEL ExpressionsGHSA-wxpp-56q6-5pcg Spring Framework Denial of Service via Unbounded Cache in SpELGHSA-4wp7-92pw-q264 Spring Framework DataBinder Case Sensitive Match ExceptionGHSA-659m-px2c-25wj Spring Framework Denial of Service via AntPathMatcherGHSA-9f52-rjqv-25qv Spring Framework Arbitrary Method Invocation in SpEL ExpressionsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.