Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-5854-jvxx-2cg9 Denial of Service in contentGHSA-x6wp-rfwh-hcx7 Regular Expression Denial of Service in contentGHSA-c429-5p7v-vgjp hoek subject to prototype pollution via the clone function.GHSA-jp4x-w63m-7wgm Prototype Pollution in hoekGHSA-q7cg-457f-vx79 joi has an uncaught RangeError on deeply nested input through recursive `link()` schemasGHSA-g64q-3vg8-8f93 Prototype Pollution in pezGHSA-6rw7-vpxm-498p qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustionGHSA-gqgv-6jq5-jjj9 Prototype Pollution Protection Bypass in qsGHSA-hrpp-h998-j3pp qs vulnerable to Prototype PollutionGHSA-2mvq-xp48-4c77 Denial of Service in subtextCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.