Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2021-46743 Key/algorithm type confusionCVE-2026-34084 PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlledCVE-2026-45034 PHPSpreadsheet has a patch bypass for CVE-2026-34084 CVE-2024-28859 Deserialization Gadget chain in Swift MailerCVE-2020-15148 Possible remote code execution via unserialize() on user input containing specially crafted stringCVE-2024-4990 Unsafe Reflection in base Component classCVE-2024-58136 yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array KeyCVE-2021-41165 CKEditor4 is an open source WYSIWYG HTML editor. In affected version a ...CVE-2024-24815 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...CVE-2024-43407 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...CVE-2026-6409 A Denial of Service (DoS) vulnerability exists in the Protobuf PHP lib ...CVE-2022-29248 Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 ...CVE-2022-31042 Guzzle is an open source PHP HTTP client. In affected versions the `Co ...CVE-2022-31043 Guzzle is an open source PHP HTTP client. In affected versions `Author ...CVE-2022-31090 Guzzle, an extensible PHP HTTP client. `Authorization` headers on requ ...CVE-2022-31091 Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` he ...CVE-2026-69246 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...CVE-2026-55568 Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain c ...CVE-2026-55767 Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar in ...CVE-2026-59883 guzzle/guzzle: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar.CVE-2026-67339 guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...CVE-2026-67353 guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...CVE-2026-67354 guzzlehttp/guzzle versions before 7.15.1 contain an information disclo ...CVE-2026-67355 guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...CVE-2026-69245 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-4574-qv3w-fcmg Deserialization of Untrusted Data in codeception/codeceptionGHSA-8xf4-w7qw-pjjw Firebase PHP-JWT key/algorithm type confusionGHSA-87m4-826x-3crx PHPSpreadsheet has a patch bypass for CVE-2026-34084 GHSA-q4q6-r8wh-5cgh PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlledGHSA-ggwg-cmwp-46r5 yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array KeyGHSA-7h26-63m7-qhf2 HTML comments vulnerability allowing to execute JavaScript codeGHSA-7r32-vfj5-c2jv Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerabilityGHSA-fq6h-4g8v-qqvm CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detectionGHSA-2x45-7fc3-mxwq php-jwt contains weak encryptionGHSA-p2gh-cfq4-4wjc Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursionGHSA-25mq-v84q-4j7r CURLOPT_HTTPAUTH option not cleared on change of originGHSA-94pj-82f3-465w Guzzle: Proxy-Authorization headers can be sent to origin serversGHSA-cwmx-hcrq-mhc3 Cross-domain cookie leakage in GuzzleGHSA-cwxw-98qj-8qjx guzzlehttp/guzzle: Dot-Only Cookie Domains Match All HostsGHSA-f283-ghqc-fg79 Guzzle: Unbounded response cookies risk denial of serviceGHSA-f2wf-25xc-69c9 Failure to strip the Cookie header on change in host or HTTP downgradeGHSA-f7vp-7xgx-4w4r Guzzle: Noncanonical cookie domain keeps subdomain scopeGHSA-g446-98w2-8p5w Guzzle: Cookie Disclosure and Injection via IP-Address DomainsGHSA-h95v-h523-3mw8 Guzzle: URI fragments disclosed in redirect Referer headersGHSA-q559-8m2m-g699 Change in port should be considered a change in originGHSA-v5mv-p594-2x33 Guzzle: Noncanonical host can bypass host-based checksGHSA-wm3w-8rrp-j577 Guzzle: Host-only cookie scope is not preservedGHSA-wpwq-4j6v-78m3 guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to CleartextGHSA-34xg-wgjx-8xph guzzlehttp/psr7 has Host Confusion via Authority ReinterpretationGHSA-c2w2-prh8-qm98 guzzlehttp/psr7: Host Confusion via Weak URI Host ValidationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.