Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
facebook-secret Discovered a Facebook Application secret, posing a risk of unauthorized access to Facebook accounts and personal data exposure.facebook-secret Discovered a Facebook Application secret, posing a risk of unauthorized access to Facebook accounts and personal data exposure.twitter-api-secret Found a Twitter API Secret, risking the security of Twitter app integrations and sensitive data access.facebook-secret Discovered a Facebook Application secret, posing a risk of unauthorized access to Facebook accounts and personal data exposure.twitter-api-key Identified a Twitter API Key, which may compromise Twitter application integrations and user data security.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2020-7610 bson: Deserialization of Untrusted Data could result in Code injection or Excessive CPU loadGHSA-4vmm-mhcq-4x9j Sandbox Bypass Leading to Arbitrary Code Execution in constantinopleCVE-2018-1000620 nodejs-cryptiles: Insecure randomness causes the randomDigits() function returns a pseudo-random data string biased to certain digitsCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerabilityCVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesCVE-2019-17426 Improper Input Validation in Automattic MongooseCVE-2023-3696 Mongoose Prototype Pollution vulnerabilityCVE-2025-23061 Mongoose search injection vulnerabilityCVE-2019-5413 nodejs-morgan: Unescaped input in compile() functionCVE-2020-7769 This affects the package nodemailer before 6.4.16. Use of crafted reci ...CVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate functionCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2021-43138 async: Prototype Pollution in asyncCVE-2021-43138 async: Prototype Pollution in asyncCVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parserCVE-2018-13863 nodejs-bson: Regular expression denial of service in decimal128.jsCVE-2019-2391 Incorrect parsing of certain JSON input may result in js-bson not corr ...CVE-2024-29041 express: cause malformed URLs to be evaluatedCVE-2018-16492 nodejs-extend: Prototype pollution can allow attackers to modify object propertiesCVE-2026-12143 form-data: form-data: Form field override via CRLF injectionCVE-2022-29167 hawk: REDoS in hawk.utils.parseHost() when parsing Host headerCVE-2018-16487 lodash: Prototype pollution in utilities functionCVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep functionCVE-2021-23337 nodejs-lodash: command injection via templateYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-v8w9-2789-6hhr Deserialization of Untrusted Data in bsonGHSA-4vmm-mhcq-4x9j Sandbox Bypass Leading to Arbitrary Code Execution in constantinopleGHSA-rq8g-5pc5-wrhr Insufficient Entropy in cryptilesGHSA-hr2v-3952-633q Prototype Pollution in deep-extendGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type ConfusionGHSA-765h-qjxv-5f44 Prototype Pollution in handlebarsGHSA-f2jv-r9rf-7988 Remote code execution in handlebars when compiling templatesGHSA-w457-6q6x-cgp9 Prototype Pollution in handlebarsGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-8687-vv9j-hgph Improper Input Validation in Automattic MongooseGHSA-9m93-w8w6-76hh Mongoose Prototype Pollution vulnerabilityGHSA-h8hf-x3f4-xwgp Mongoose Vulnerable to Prototype Pollution in Schema ObjectGHSA-m7xq-9374-9rvx Mongoose search injection vulnerabilityGHSA-vg7j-7cwx-8wgw Mongoose search injection vulnerabilityGHSA-gwg9-rgvj-4h5j Code Injection in morganGHSA-48ww-j4fc-435p Command injection in nodemailerGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.