Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderGHSA-2x2g-32r7-p4x8 Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProviderGHSA-5qcv-4rpc-jp93 Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race ConditionGHSA-vgq5-3255-v292 Apache Kafka Client Arbitrary File Read and Server Side Request Forgery VulnerabilityGHSA-wf66-mphr-4c4r Apache Kafka exposes sensitive information in its DEBUG logsGHSA-rqfh-9r24-8c9r AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertionGHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS ConditionGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-3pjw-73gf-8qr5 jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategyGHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiationGHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)GHSA-4265-ccf5-phj5 Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 fileGHSA-4g9r-vxhx-9pgx Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP fileGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-3pxv-7cmr-fjr4 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden charactersGHSA-6hg6-v5c8-fphq Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configurationGHSA-vc5p-v9hr-52mj Apache Log4j does not verify the TLS hostname in its Socket AppenderGHSA-cmp6-m4wj-q63q yawkat LZ4 Java has a possible information leak in Java safe decompressorGHSA-vqf4-7m7x-wgfc LZ4 Java Compression has Out-of-bounds memory operations which can cause DoSGHSA-xx22-p4ch-683r LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array rangesGHSA-55g7-9cwv-5qfv snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impactGHSA-fjpj-2g6w-x25r snappy-java's Integer Overflow vulnerability in compress leads to DoSGHSA-pqr6-cmr2-h8hf snappy-java's Integer Overflow vulnerability in shuffle leads to DoSCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.