Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
CVE-2025-64459 django: Django SQL injectionCVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodiesCVE-2021-41945 Encode OSS httpx < 0.23.0 is affected by improper input validation in ...CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injectionCVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code ExecutionCVE-2025-57833 django: Django SQL injection in FilteredRelation column aliasesCVE-2025-59681 django: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB1CVE-2025-64458 Django: Denial-of-service vulnerability in Django on WindowsCVE-2024-56374 django: potential denial-of-service vulnerability in IPv6 validationCVE-2025-13372 django: Django: SQL injection in FilteredRelation column aliasesCVE-2025-26699 django: Potential denial-of-service vulnerability in django.utils.text.wrap()CVE-2025-27556 django: Django DoS Unicode AttackCVE-2025-32873 django: Django StripTags Denial of ServiceCVE-2025-48432 django: Django Path Injection VulnerabilityCVE-2025-64460 Django: Django: Algorithmic complexity in XML Deserializer leads to denial of serviceCVE-2026-53877 django: Django: Information disclosure via heap buffer over-read in GDALRasterCVE-2026-53878 django: Django: HTTP header injection via DomainNameValidator accepting newlinesCVE-2024-6839 corydolphin/flask-cors version 4.0.1 contains an improper regex path m ...CVE-2024-6844 A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inc ...CVE-2024-6866 corydolphin/flask-cors version 4.01 contains a vulnerability where the ...CVE-2026-42215 GitPython is a python library used to interact with Git repositories. ...CVE-2026-42284 GitPython is a python library used to interact with Git repositories. ...CVE-2026-44243 GitPython: GitPython: Arbitrary file write via crafted reference pathsCVE-2026-44244 GitPython is a python library used to interact with Git repositories. ...GHSA-2f96-g7mh-g2hx GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklistYour dependencies cross-checked against the OSV vulnerability database.
Nothing found by this check. ✓
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.