Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2017-1000487 plexus-utils: Mishandled strings in Commandline class allow for command injectionCVE-2022-0839 liquibase: Improper Restriction of XML External EntityCVE-2022-22970 springframework: DoS via data binding to multipartFile or servlet partCVE-2022-22968 Framework: Data Binding Rules VulnerabilityCVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...CVE-2015-5211 Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4 ...CVE-2016-5007 spring: Path matching inconsistencyCVE-2018-1272 spring-framework: Multipart content pollutionCVE-2014-3578 Framework: Directory traversalCVE-2018-1257 spring-framework: ReDoS Attack with spring-messagingCVE-2018-1271 spring-framework: Directory traversal vulnerability with static resources on Windows filesystemsCVE-2023-32697 sqlite-jdbc: Remote code execution when JDBC url is attacker controlledCVE-2022-4244 codehaus-plexus: Directory TraversalCVE-2025-67030 org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile methodCVE-2022-4245 codehaus-plexus: XML External Entity (XXE) InjectionCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2022-42890 batik: Untrusted code execution in Apache XML Graphics BatikCVE-2022-44729 batik: Server-Side Request Forgery vulnerabilityCVE-2022-38648 batik: Server-Side Request ForgeryCVE-2022-44730 batik: Server-Side Request Forgery vulnerabilityYour dependencies cross-checked against the OSV vulnerability database.
GHSA-qg25-hgjv-cg9q Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache GroovyGHSA-xphj-m9cc-8fmq Deserialization of Untrusted Data in GroovyGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-jvfv-hrrc-6q72 Improper Restriction of XML External Entity Reference in LiquibaseGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.