Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-3651 python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()CVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputsCVE-2024-35195 requests: subsequent requests to the same host ignore cert verificationCVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLsCVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creationCVE-2025-66418 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionCVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed dataCVE-2026-21441 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)CVE-2026-44431 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headersCVE-2024-37891 urllib3: proxy-authorization request header is not stripped during cross-origin redirectsCVE-2025-50181 urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiationCVE-2025-50182 urllib3: urllib3 does not control redirects in browsers and Node.jsCVE-2024-39689 python-certifi: Remove root certificates from `GLOBALTRUST` from the root storeYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2024-230 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.PYSEC-2024-60 A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings,PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions priorPYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1472 Jinja has a sandbox breakout through malicious filenamesPYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLsPYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=FalsePYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system tePYSEC-2025-49 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to versioPYSEC-2026-1918 setuptools vulnerable to Command Injection via package URLPYSEC-2026-3447 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude,PYSEC-2026-141 urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=FalPYSEC-2026-1994 urllib3 streaming API improperly handles highly compressed dataPYSEC-2026-1995 urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirectsPYSEC-2026-1996 Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)PYSEC-2026-1997 urllib3 does not control redirects in browsers and Node.jsPYSEC-2026-1998 urllib3 allows an unbounded number of links in the decompression chainPYSEC-2026-1999 urllib3 redirects are not disabled when retries are disabled on PoolManager instantiationPYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to disPYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rePYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLsPYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=FalsePYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system teCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.