Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2022-1650 eventsource: Exposure of Sensitive InformationCVE-2022-0686 npm-url-parse: Authorization bypass through user-controlled keyCVE-2022-0686 npm-url-parse: Authorization bypass through user-controlled keyCVE-2026-54466 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...CVE-2021-23424 nodejs-ansi-html: ReDoS via crafted stringGHSA-hxcm-v35h-mg2x Prototype Pollution in querystringifyGHSA-hxcm-v35h-mg2x Prototype Pollution in querystringifyCVE-2021-24033 nodejs-react-dev-utils: function getProcessForPort concatenates input argument into a command stringCVE-2018-3774 nodejs-url-parse: incorrect hostname in url parsingCVE-2020-8124 npmjs-url-parse: Improper validation of protocol of the returned URLCVE-2021-27515 nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromiseCVE-2021-3664 nodejs-url-parse: URL Redirection to Untrusted SiteCVE-2022-0512 nodejs-url-parse: authorization bypass through user-controlled keyCVE-2022-0639 npm-url-parse: Authorization Bypass Through User-Controlled KeyCVE-2022-0691 npm-url-parse: authorization bypass through user-controlled keyCVE-2018-3774 nodejs-url-parse: incorrect hostname in url parsingCVE-2020-8124 npmjs-url-parse: Improper validation of protocol of the returned URLCVE-2021-27515 nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromiseCVE-2021-3664 nodejs-url-parse: URL Redirection to Untrusted SiteCVE-2022-0512 nodejs-url-parse: authorization bypass through user-controlled keyCVE-2022-0639 npm-url-parse: Authorization Bypass Through User-Controlled KeyCVE-2022-0691 npm-url-parse: authorization bypass through user-controlled keyCVE-2024-29180 webpack-dev-middleware: lack of URL validation may lead to file leakCVE-2026-54490 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...CVE-2020-7662 npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parserYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-8w4h-3cm3-2pm2 Out-of-bounds Read in atobGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-cpq7-6gpm-g9rc cipher-base is missing type checks, leading to hash rewind and passing on crafted dataGHSA-rq8g-5pc5-wrhr Insufficient Entropy in cryptilesGHSA-hr2v-3952-633q Prototype Pollution in deep-extendGHSA-phwq-j96m-2c2q ejs template injection vulnerabilityGHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)GHSA-6h5x-7c5m-7cr7 Exposure of Sensitive Information in eventsourceGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-qh2h-chj9-jffq Growl before 1.10.0 vulnerable to Command InjectionGHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type ConfusionGHSA-765h-qjxv-5f44 Prototype Pollution in handlebarsGHSA-f2jv-r9rf-7988 Remote code execution in handlebars when compiling templatesGHSA-w457-6q6x-cgp9 Prototype Pollution in handlebarsGHSA-86wf-436m-h424 Resource Exhaustion Denial of Service in http-proxy-agent GHSA-8g7p-74h8-hg48 Denial of Service in https-proxy-agentGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-675m-85rw-j3w4 Prototype Pollution in just-extendGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.