Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2026-27962 authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerabilityCVE-2025-59420 authlib: Authlib RFC violationCVE-2025-61920 authlib: Authlib Denial of ServiceCVE-2026-28490 authlib: Authlib: Information disclosure due to cryptographic padding oracle in JWE RSA1_5CVE-2026-28498 authlib: Authlib: Authentication bypass via forged OpenID Connect ID TokensCVE-2025-62706 authlib: Authlib : JWE zip=DEF decompression bomb enables DoSCVE-2025-68158 Authlib: Authlib: Cross-Site Request Forgery due to improper session management in state storageCVE-2026-41425 authlib: Authlib: Cross-Site Request Forgery (CSRF) vulnerability in OAuth cache featureCVE-2026-41479 Authlib is a Python library which builds OAuth and OpenID Connect serv ...CVE-2026-44681 Authlib is a Python library which builds OAuth and OpenID Connect serv ...CVE-2026-32274 black: Black: Arbitrary file writes from unsanitized user input in cache file nameCVE-2025-68480 github.com/marshmallow-code/marshmallow: Marshmallow: Denial of Service via crafted request to Schema.load functionCVE-2025-71176 pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handlingCVE-2026-59890 setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)CVE-2026-22702 virtualenv: virtualenv: Local attacker can redirect file operations via TOCTOU race conditionYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-pypi-code-execution code-execution match in pyarrow 25.0.0guarddog-pypi-code-execution code-execution match in pandas 3.0.5guarddog-pypi-obfuscation obfuscation match in passlib 1.7.4guarddog-pypi-shady-links shady-links match in tqdm 4.70.0guarddog-pypi-clipboard-access clipboard-access match in pandas 3.0.5guarddog-pypi-shady-links shady-links match in Pygments 2.20.0A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.