gitsafehub
github.com/anikchand461/ecomate ↗

anikchand461/ecomate

scanned 2026-08-11 · git a43248b
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets3Vulnerable dependencies206Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 3 found · 3 serious

API keys, passwords or tokens committed into the repo.

  • Serious gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.
    ecofix/climate_tracker/templates/submit_observation.html:156
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.
    ecofix/climate_tracker/templates/map.html:141
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    ecofix/ecofix/json_file.json:5
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 206 found · 5 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2025-64459 django: Django SQL injection
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-64459). Fix: Update that package to its patched version.
  • Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious CVE-2021-41945 Encode OSS httpx < 0.23.0 is affected by improper input validation in ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-41945). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-57833 django: Django SQL injection in FilteredRelation column aliases
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-57833). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-59681 django: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB1
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-59681). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-64458 Django: Denial-of-service vulnerability in Django on Windows
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-64458). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56374 django: potential denial-of-service vulnerability in IPv6 validation
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-56374). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-13372 django: Django: SQL injection in FilteredRelation column aliases
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-13372). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-26699 django: Potential denial-of-service vulnerability in django.utils.text.wrap()
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-26699). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27556 django: Django DoS Unicode Attack
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-27556). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-32873 django: Django StripTags Denial of Service
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-32873). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-48432 django: Django Path Injection Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-48432). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-64460 Django: Django: Algorithmic complexity in XML Deserializer leads to denial of service
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-64460). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53877 django: Django: Information disclosure via heap buffer over-read in GDALRaster
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-53877). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53878 django: Django: HTTP header injection via DomainNameValidator accepting newlines
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-53878). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6839 corydolphin/flask-cors version 4.0.1 contains an improper regex path m ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-6839). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6844 A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inc ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-6844). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6866 corydolphin/flask-cors version 4.01 contains a vulnerability where the ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-6866). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42215 GitPython is a python library used to interact with Git repositories. ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-42215). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42284 GitPython is a python library used to interact with Git repositories. ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-42284). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44243 GitPython: GitPython: Arbitrary file write via crafted reference paths
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44243). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44244 GitPython is a python library used to interact with Git repositories. ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44244). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2f96-g7mh-g2hx GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
    requirements.txt
    A package you depend on has a known security hole (GHSA-2f96-g7mh-g2hx). Fix: Update that package to its patched version.
… 181 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner none found ✓

Your dependencies cross-checked against the OSV vulnerability database.

Nothing found by this check. ✓

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog couldn’t run

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:ERROR: Error while scanning. Received 'utf-8' codec can't decode byte 0xff in position 0: invalid start byte Traceback (

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.