Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2021-26291 maven: Block repositories using http by defaultCVE-2017-1000487 plexus-utils: Mishandled strings in Commandline class allow for command injectionCVE-2021-26291 maven: Block repositories using http by defaultCVE-2017-1000487 plexus-utils: Mishandled strings in Commandline class allow for command injectionCVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gsonCVE-2022-4244 codehaus-plexus: Directory TraversalCVE-2025-67030 org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile methodCVE-2022-4245 codehaus-plexus: XML External Entity (XXE) InjectionCVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gsonCVE-2022-4244 codehaus-plexus: Directory TraversalCVE-2025-67030 org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile methodCVE-2022-4245 codehaus-plexus: XML External Entity (XXE) InjectionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-rcjc-c4pj-xxrp Apache Derby: LDAP injection vulnerability in authenticatorGHSA-77xx-rxvh-q682 HyperSQL DataBase vulnerable to remote code execution when processing untrusted inputGHSA-24rp-q3w6-vc56 org.postgresql:postgresql vulnerable to SQL Injection via line comment generationGHSA-24rp-q3w6-vc56 org.postgresql:postgresql vulnerable to SQL Injection via line comment generationGHSA-qg25-hgjv-cg9q Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache GroovyGHSA-xphj-m9cc-8fmq Deserialization of Untrusted Data in GroovyGHSA-2f88-5hg8-9x2x Origin Validation Error in Apache MavenGHSA-8vhq-qq4p-grq3 OS Command Injection in Plexus-utilsGHSA-4jrv-ppp4-jm57 Deserialization of Untrusted Data in GsonGHSA-22wj-vf5f-wrvj Password exposure in H2 Database GHSA-7rpj-hg47-cx62 Improper Restriction of XML External Entity Reference in com.h2database:h2.GHSA-g76j-4cxx-23h9 Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors JavaGHSA-m6vm-37g8-gqvh MySQL Connectors takeover vulnerabilityGHSA-w6f2-8wx4-47r5 Incorrect Authorization in MySQL Connector JavaGHSA-33g6-495w-v8j2 Snowflake JDBC uses insecure temporary credential cache file permissionsGHSA-4g3j-c4wg-6j7x Snowflake JDBC vulnerable to command injection via SSO URL authenticationGHSA-7hpq-3g6w-pvhf Snowflake JDBC allows an untrusted search path on WindowsGHSA-f686-hw9c-xw9c Snowflake JDBC Security AdvisoryGHSA-562r-vg33-8x8h TemporaryFolder on unix-like systems does not limit access to created filesGHSA-88cc-g835-76rp Improper Restriction of XML External Entity ReferenceGHSA-98qh-xjc8-98pq pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoSGHSA-r38f-c4h4-hqq2 PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column namesGHSA-v7wg-cpwc-24m4 pgjdbc Does Not Check Class Instantiation when providing Plugin ClassesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.