Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gsonCVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-4jrv-ppp4-jm57 Deserialization of Untrusted Data in GsonGHSA-7r82-7xv7-xcpj Cross-site scripting in Apache HttpClientGHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-hmr7-m48g-48f6 Jetty accepts "+" prefixed value in Content-LengthGHSA-qh8g-58pp-2wxh Eclipse Jetty URI parsing of invalid authorityGHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-g8m5-722r-8whq Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksGHSA-q4rv-gq96-w7c5 **UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate requestGHSA-qw69-rqj8-6qw8 OutOfMemoryError for large multipart without filename in Eclipse JettyGHSA-wjpw-4j6x-6rwh org.eclipse.jetty:jetty-http has different parsing of invalid URIsGHSA-p26g-97m4-6q7c Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookiesGHSA-58qw-p7qm-5rvh Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarationsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.