Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2025-66456 Elysia vulnerable to prototype pollution with multiple standalone schema validationCVE-2025-66457 Elysia affected by arbitrary code injection through cookie configCVE-2026-30837 Elysia has a string URL format ReDoSCVE-2026-31865 Elysia Cookie Value Prototype PollutionCVE-2026-31808 file-type: file-type: Denial of Service due to infinite loop in ASF file parsingCVE-2026-32630 file-type: file-type: Denial of Service via excessive memory growth from crafted ZIP filesCVE-2026-33732 srvx is vulnerable to middleware bypass via absolute URI in request line Your dependencies cross-checked against the OSV vulnerability database.
GHSA-hxj9-33pp-j2cc Elysia vulnerable to prototype pollution with multiple standalone schema validationGHSA-8hq9-phh3-p2wp Elysia Cookie Value Prototype PollutionGHSA-8vch-m3f4-q8jf Elysia affected by arbitrary code injection through cookie configGHSA-f45g-68q3-5w8x Elysia has a string URL format ReDoSGHSA-5v7r-6r5c-r473 file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-headerGHSA-j47w-4g3g-c36v file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entryGHSA-p36q-q72m-gchr srvx is vulnerable to middleware bypass via absolute URI in request line Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.