Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747CVE-2022-21797 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary ...CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code ExecutionCVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filterCVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filterCVE-2024-34064 jinja2: accepts keys containing non-attribute charactersCVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format methodCVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format methodCVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequencesCVE-2021-20270 python-pygments: Infinite loop in SML lexer may lead to DoSCVE-2021-27291 python-pygments: ReDoS in multiple lexersCVE-2022-40896 pygments: ReDoS in pygmentsCVE-2022-40899 python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web serverCVE-2021-3828 nltk is vulnerable to Inefficient Regular Expression ComplexityCVE-2021-3842 nltk is vulnerable to Inefficient Regular Expression ComplexityCVE-2021-43854 NLTK (Natural Language Toolkit) is a suite of open source Python modul ...CVE-2024-39705 NLTK through 3.8.1 allows remote code execution if untrusted packages ...CVE-2026-0846 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` functionCVE-2026-33231 nltk: NLTK: Denial of Service via unauthenticated remote shutdownCVE-2026-54293 nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`CVE-2026-33230 nltk: NLTK: Script execution via reflected cross-site scripting in WordNet BrowserCVE-2023-32309 PyMdown Extensions is a set of extensions for the `Python-Markdown` ma ...CVE-2024-52804 python-tornado: Tornado has HTTP cookie parsing DoS vulnerabilityCVE-2025-47287 tornado: Tornado Multipart Form-Data Denial of ServiceCVE-2025-67725 tornado: Tornado Quadratic DoS via Repeated Header CoalescingYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or PYSEC-2022-288 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.PYSEC-2026-96 A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path PYSEC-2026-99 NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verificPYSEC-2022-42992 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clonePYSEC-2023-137 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.PYSEC-2026-2161 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options))PYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2026-89 Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-MaPYSEC-2021-140 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only PYSEC-2021-141 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity anPYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.PYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.PYSEC-2022-42991 An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.PYSEC-2021-356 nltk is vulnerable to Inefficient Regular Expression ComplexityPYSEC-2021-859 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnePYSEC-2022-5 nltk is vulnerable to Inefficient Regular Expression ComplexityPYSEC-2024-167 NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_percPYSEC-2026-2078 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.loPYSEC-2026-2085 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.