Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-14322 Pallets Werkzeug vulnerable to Path TraversalCVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerabilityCVE-2023-25577 python-werkzeug: high resource usage when parsing multipart form data with many fieldsCVE-2024-34069 python-werkzeug: user may execute code on a developer's machineCVE-2016-10516 python-werkzeug: Cross-site scripting in render_full function in debug/tbtools.pyCVE-2020-28724 python-werkzeug: open redirect via double slash in the URLCVE-2024-49766 werkzeug: python-werkzeug: Werkzeug safe_join not safe on WindowsCVE-2025-66221 Werkzeug: Werkzeug: Denial of service via Windows device names in path segmentsCVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensionsCVE-2026-27199 Werkzeug safe_join() allows Windows special device namesCVE-2023-23934 python-werkzeug: cookie prefixed with = can shadow unprefixed cookieYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2017-43 Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote PYSEC-2019-140 Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.PYSEC-2020-157 Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.PYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are apPYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a smPYSEC-2026-1065 Pallets Werkzeug vulnerable to Path TraversalPYSEC-2026-2043 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainPYSEC-2026-2044 Werkzeug safe_join() allows Windows special device names with compound extensionsPYSEC-2026-2045 Werkzeug safe_join not safe on WindowsPYSEC-2026-2046 Werkzeug safe_join() allows Windows special device namesPYSEC-2026-2320 Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previouPYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions priorPYSEC-2017-43 Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote PYSEC-2019-140 Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.PYSEC-2020-157 Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.PYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are apPYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a smPYSEC-2026-1065 Pallets Werkzeug vulnerable to Path TraversalPYSEC-2026-2043 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainPYSEC-2026-2044 Werkzeug safe_join() allows Windows special device names with compound extensionsPYSEC-2026-2045 Werkzeug safe_join not safe on WindowsPYSEC-2026-2046 Werkzeug safe_join() allows Windows special device namesPYSEC-2026-2320 Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previouPYSEC-2023-57 Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised applicationPYSEC-2023-57 Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised applicationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-pypi-obfuscation obfuscation match in Sphinx 9.1.0A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.