Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-9h52-p55h-vw2f Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by defaultGHSA-j975-95f5-7wqh MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of ServiceGHSA-65pc-fj4g-8rjx Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fixGHSA-59g5-xgcq-4qw3 Denial of service (DoS) via deformation `multipart/form-data` boundaryGHSA-mj87-hwqh-73pj python-multipart affected by Denial of Service via large multipart preamble or epilogue dataGHSA-pp6c-gr5w-3c5g python-multipart has Denial of Service via unbounded multipart part headersGHSA-wp53-j4wj-2cfg Python-Multipart has Arbitrary File Write via Non-Default ConfigurationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-pypi-shady-links shady-links match in mcp 1.27.2A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 1.9/10scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Code-Review Code-Review scored 0: Found 0/5 approved changesets -- score normalized to 0scorecard-Contributors Contributors scored 0: project has 0 contributing companies or organizations -- score normalized to 0scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Maintained Maintained scored 0: project was created within the last 90 days. Please review its contents carefullyscorecard-SAST SAST scored 0: no SAST tool detectedscorecard-Security-Policy Security-Policy scored 0: security policy file not detected