Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2026-47065 mina: mina: Arbitrary Code Execution via Deserialization BypassCVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionCVE-2026-69152 brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arraysCVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-18446 fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authorityCVE-2026-10532 Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...CVE-2026-1225 ch.qos.logback/logback-core: Malicious logback.xml configuration file allows instantiation of arbitrary classesCVE-2026-9828 Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...CVE-2025-57349 messageformat has a prototype pollution vulnerabilityYour dependencies cross-checked against the OSV vulnerability database.
GHSA-3vx3-xf6q-r5xp Exposure of Resource to Wrong Sphere in Apache TomcatGHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly appliedGHSA-cw54-59pw-4g8c Apache Tomcat Improper Access Control vulnerabilityGHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown userGHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validatedGHSA-xcpr-7mr4-h4xq Apache Tomcat - Authentication BypassGHSA-fpj8-gq4v-p354 Apache Tomcat - Client certificate verification bypassMAL-2025-21003 Malicious code in fs (npm)GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-2m8v-j782-fhvr Socket.IO: Zero-attachment Memory ExhaustionGHSA-344f-f5vg-2jfj Potential remote code execution in Apache TomcatGHSA-5mp6-jrq3-r938 Apache Tomcat: LockOutRealm treats user names as case-sensitiveGHSA-8qq4-8jvq-mfw4 Exposure of Sensitive Information to an Unauthorized Actor in Apache TomcatGHSA-fv25-8xcx-gqjc Apache Tomcat - WebSocket authentication header exposureGHSA-gx5v-xp9w-j4cg Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handlingGHSA-jjpq-gp5q-8q6w Cross-site scripting in Apache TomcatGHSA-v646-rx6w-r3qq Improper Access Control in Apache TomcatGHSA-xjgh-84hx-56c5 Unrestricted Upload of File with Dangerous Type Apache TomcatGHSA-563x-q5rq-57qp Apache Tomcat has an HTTP Request/Response Smuggling vulnerabilityGHSA-jc7p-5r39-9477 Improper Input Validation in Apache TomcatGHSA-2qqx-w9hr-q5gx angular vulnerable to regular expression denial of service via the $resource serviceGHSA-2vrf-hf26-jrp5 angular vulnerable to regular expression denial of service via the angular.copy() utilityGHSA-4w4v-5hc9-xrr2 angular vulnerable to super-linear runtime due to backtrackingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.