Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2025-64459 django: Django SQL injectionCVE-2025-64459 django: Django SQL injectionCVE-2025-64459 django: Django SQL injectionCVE-2025-54368 uv allows ZIP payload obfuscation through parsing differentialsGHSA-4gg8-gxpx-9rph uv is vulnerable to arbitrary file write through entry point namesGHSA-pqhf-p39g-3x64 uv allows ZIP payload obfuscation through parsing differentialsCVE-2025-59681 django: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB1CVE-2025-64458 Django: Denial-of-service vulnerability in Django on WindowsCVE-2026-1207 Django: Django: SQL Injection via RasterField band index parameterCVE-2026-1287 Django: Django: SQL Injection via crafted column aliasesCVE-2026-25673 django: Django: Denial of Service via slow URL normalization on WindowsCVE-2026-33034 Django: Django: Denial of Service via missing or understated Content-Length header in ASGI requestsCVE-2026-3902 Django: Django: Header spoofing via ambiguous header mappingCVE-2025-13372 django: Django: SQL injection in FilteredRelation column aliasesCVE-2025-64460 Django: Django: Algorithmic complexity in XML Deserializer leads to denial of serviceCVE-2026-1312 Django: Django: SQL injection via crafted column aliases in QuerySet.order_by()CVE-2026-33033 Django: Django: Performance degradation via excessive whitespace in multipart uploadsCVE-2026-53877 django: Django: Information disclosure via heap buffer over-read in GDALRasterCVE-2026-53878 django: Django: HTTP header injection via DomainNameValidator accepting newlinesCVE-2026-5766 django: Django: Service degradation via understated Content-Length header in ASGI requestsCVE-2025-59681 django: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB1CVE-2025-64458 Django: Denial-of-service vulnerability in Django on WindowsCVE-2026-1207 Django: Django: SQL Injection via RasterField band index parameterCVE-2026-1287 Django: Django: SQL Injection via crafted column aliasesCVE-2026-25673 django: Django: Denial of Service via slow URL normalization on WindowsYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2025-106 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injecPYSEC-2025-108 An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to PYSEC-2026-52 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Add permissions on inline model instances were not validated on submission of
forged `POST` data in `GenericInlinPYSEC-2025-106 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injecPYSEC-2025-108 An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to PYSEC-2026-52 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Add permissions on inline model instances were not validated on submission of
forged `POST` data in `GenericInlinPYSEC-2025-106 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injecPYSEC-2025-108 An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to PYSEC-2026-52 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Add permissions on inline model instances were not validated on submission of
forged `POST` data in `GenericInlinPYSEC-2026-52 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Add permissions on inline model instances were not validated on submission of
forged `POST` data in `GenericInlinPYSEC-2026-2120 Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use fromPYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.PYSEC-2026-1845 pytest has vulnerable tmpdir handlingPYSEC-2026-2001 uv allows ZIP payload obfuscation through parsing differentialsPYSEC-2026-2295 A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that eGHSA-52cp-r559-cp3m js-yaml: YAML merge-key chains can force quadratic CPU consumptionGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedGHSA-h67p-54hq-rp68 JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliasesGHSA-52cp-r559-cp3m js-yaml: YAML merge-key chains can force quadratic CPU consumptionGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedGHSA-h67p-54hq-rp68 JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliasesGHSA-f88m-g3jw-g9cj sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591GHSA-4cwx-7wf7-3272 undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesGHSA-8xcm-r25x-g524 undici vulnerable to downstream response desynchronization via retry interceptorGHSA-hm92-r4w5-c3mj undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuseCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.