Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2026-32933 AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled RecursionCVE-2018-8269 Denial of service in ASP.NET CoreCVE-2020-1045 dotnet: ASP.NET cookie prefix spoofing vulnerabilityCVE-2022-29117 dotnet: malicious content causes high CPU and memory usageCVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonCVE-2024-21319 dotnet: .NET Denial of Service VulnerabilityCVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonCVE-2018-8292 Core: information disclosure due to authentication information exposed in a redirectCVE-2019-0820 dotnet: timeouts for regular expressions are not enforcedCVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonCVE-2018-8292 Core: information disclosure due to authentication information exposed in a redirectCVE-2019-0820 dotnet: timeouts for regular expressions are not enforcedCVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonCVE-2018-8292 Core: information disclosure due to authentication information exposed in a redirectCVE-2019-0820 dotnet: timeouts for regular expressions are not enforcedCVE-2018-8292 Core: information disclosure due to authentication information exposed in a redirectCVE-2019-0820 dotnet: timeouts for regular expressions are not enforcedYour dependencies cross-checked against the OSV vulnerability database.
GHSA-rvv3-g6hj-g44x AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled RecursionGHSA-mv2r-q4g5-j8q5 Denial of service in ASP.NET CoreGHSA-3rq8-h3gj-r5c6 .NET Denial of Service VulnerabilityGHSA-hxrm-9w7p-39cc Cookie parsing failureGHSA-5crp-9r3c-p9vr Improper Handling of Exceptional Conditions in Newtonsoft.JsonGHSA-59j7-ghrg-fj52 Microsoft ASP.NET Core project templates vulnerable to denial of serviceGHSA-5crp-9r3c-p9vr Improper Handling of Exceptional Conditions in Newtonsoft.JsonGHSA-7jgj-8wvc-jh57 .NET Core Information DisclosureGHSA-cmhx-cq75-c4mj Regular Expression Denial of Service in System.Text.RegularExpressionsGHSA-5crp-9r3c-p9vr Improper Handling of Exceptional Conditions in Newtonsoft.JsonGHSA-7jgj-8wvc-jh57 .NET Core Information DisclosureGHSA-cmhx-cq75-c4mj Regular Expression Denial of Service in System.Text.RegularExpressionsGHSA-5crp-9r3c-p9vr Improper Handling of Exceptional Conditions in Newtonsoft.JsonGHSA-7jgj-8wvc-jh57 .NET Core Information DisclosureGHSA-cmhx-cq75-c4mj Regular Expression Denial of Service in System.Text.RegularExpressionsGHSA-7jgj-8wvc-jh57 .NET Core Information DisclosureGHSA-cmhx-cq75-c4mj Regular Expression Denial of Service in System.Text.RegularExpressionsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.