Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2023-45133 babel: arbitrary code executionCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2026-73420 Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassCVE-2026-73420 Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassCVE-2026-73421 Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)CVE-2025-61686 react-router: React Router has Path Traversal in File Session StorageCVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2026-33937 handlebars.js: Handlebars: Remote Code Execution via crafted Abstract Syntax Tree object in compile()CVE-2025-61927 happy-dom: Happy-DOM VM Context EscapeCVE-2024-21508 mysql2: Remote Code ExecutionCVE-2024-21511 mysql2: Arbitrary Code Injection due to improper sanitization of the timezone parameterCVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2025-9288 sha.js: Missing type checks leading to hash rewind and passing on crafted dataCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2026-47429 vitest: Vitest: Arbitrary code execution and information disclosure via path traversalCVE-2021-44906 minimist: prototype pollutionCVE-2019-5413 nodejs-morgan: Unescaped input in compile() functionCVE-2023-45133 babel: arbitrary code executionCVE-2026-1774 CASL Ability is Vulnerable to Prototype PollutionCVE-2026-22599 Strapi Vulnerable to SQL Injection in Content Type BuilderCVE-2026-27886 Strapi may leak sensitive data via relational filtering due to lack of query sanitizationGHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)CVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2025-7783 form-data: Unsafe random function in form-dataYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-7rqj-j65f-68wh Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-7rqj-j65f-68wh Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-7rqj-j65f-68wh Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-8fpg-xm3f-6cx3 Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)GHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-9583-h5hc-x8cw React Router has Path Traversal in File Session StorageGHSA-9583-h5hc-x8cw React Router has Path Traversal in File Session StorageGHSA-5rq4-664w-9x2c Basic FTP has Path Traversal Vulnerability in its downloadToDir() methodGHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type ConfusionGHSA-37j7-fg3j-429f Happy DOM: VM Context Escape can lead to Remote Code ExecutionGHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype PollutionGHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype PollutionGHSA-4rch-2fh8-94vw MySQL2 for Node Arbitrary Code InjectionGHSA-fpw7-j2hg-69v5 mysql2 Remote Code Execution (RCE) via the readCodeFor functionGHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-95m3-7q98-8xr5 sha.js is missing type checks leading to hash rewind and passing on crafted dataCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.