Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2026-8466 Allocation of Resources Without Limits or Throttling vulnerability in ...CVE-2026-43966 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Reque ...CVE-2026-43970 Improper Handling of Highly Compressed Data (Data Amplification) vulne ...CVE-2026-7790 Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ...CVE-2026-43968 CVE-2026-43968 affecting package rabbitmq-server for versions less than 3.13.7-5CVE-2026-32686 Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoSCVE-2026-47071 Hackney: `ssl:connect/2` post-handshake upgrade has no timeoutCVE-2026-47075 Hackney has CR/LF injection in query parameterCVE-2026-47076 Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded hostCVE-2023-50966 erlang-jose: Denial-of-service due to high CPU consumptionCVE-2022-42975 Phoenix before 1.6.14 mishandles check_origin wildcardingCVE-2026-8468 Plug: Unbounded buffer accumulation in multipart header parsing causes denial of serviceCVE-2026-32688 Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustionCVE-2026-32687 Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3`CVE-2025-27152 axios: Possible SSRF and Credential Leakage via Absolute URL in axios RequestsCVE-2026-25639 axios: Axios affected by Denial of Service via __proto__ Key in mergeConfigCVE-2026-42033 axios: Axios: HTTP Transport Hijacking via Prototype PollutionCVE-2026-42035 axios: Axios: Arbitrary HTTP header injection via prototype pollutionCVE-2026-42043 axios: Axios: NO_PROXY bypass via crafted URLCVE-2026-44486 axios: Axios: Information disclosure of proxy credentials via HTTP redirectsCVE-2026-44487 axios: Axios: Information disclosure of proxy credentials via redirect flowsCVE-2026-44492 axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalizationCVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerabilityCVE-2026-44496 axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie nameYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryEEF-CVE-2026-65624 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory ExhaustionEEF-CVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboyGHSA-w4f7-4cxr-rv3c cowboy and gun affected by an HTTP Request/Response Splitting vulnerabilityEEF-CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2EEF-CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1EEF-CVE-2026-43970 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY FrameEEF-CVE-2026-59248 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoSEEF-CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoSEEF-CVE-2026-32686 Unbounded exponent in decimal enables unauthenticated DoSEEF-CVE-2026-47071 SOCKS5 TLS upgrade ignores caller timeout in hackneyEEF-CVE-2026-47075 CR/LF injection in query parameter in hackneyEEF-CVE-2026-47076 SSRF allowlist bypass via percent-encoded host in hackneyGHSA-vq52-99r9-h5pw Server-side Request Forgery (SSRF) in hackneyGHSA-9mg4-v392-8j68 erlang-jose vulnerable to denial of service via large p2c valueEEF-CVE-2026-56811 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of serviceEEF-CVE-2026-56812 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiffGHSA-p8f7-22gq-m7j9 Phoenix before 1.6.14 mishandles check_origin wildcardingEEF-CVE-2026-56814 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)EEF-CVE-2026-8468 Unbounded buffer accumulation in multipart header parsing causes denial of service in plugEEF-CVE-2026-32688 Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboyEEF-CVE-2026-32687 SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3GHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-3g43-6gmg-66jw axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.