Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2025-66414 Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by defaultCVE-2026-0621 Anthropic's MCP TypeScript SDK has a ReDoS vulnerabilityCVE-2026-25536 @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leakCVE-2026-1664 Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email RoutingCVE-2026-1721 Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handlerGHSA-w5cr-2qhr-jqc5 Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground siteCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2025-13466 body-parser: body-parser denial of serviceCVE-2025-9910 jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBeginCVE-2025-66400 mdast-util-to-hast: mdast-util-to-hast: Markdown code elements can appear as regular page contentCVE-2026-67213 nanoid: nanoid: Denial of Service via infinite loop in random ID generationCVE-2026-67214 nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...CVE-2026-67213 nanoid: nanoid: Denial of Service via infinite loop in random ID generationCVE-2026-67214 nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...CVE-2026-4926 path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressionsCVE-2026-4923 path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcardsCVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsingCVE-2026-8723 ### Summary `qs.stringify` throws `TypeError` when called with `arr ...CVE-2025-48985 Vercel’s AI SDK's filetype whitelists can be bypassed when uploading filesCVE-2026-12590 body-parser: body-parser: Denial of Service via invalid limit optionCVE-2026-2391 qs: qs's arrayLimit bypass in comma parsing allows denial of serviceYour dependencies cross-checked against the OSV vulnerability database.
GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-866g-f22w-33x8 @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issueGHSA-345p-7cg4-v4c7 @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuseGHSA-8r9q-7v3j-jr4g Anthropic's MCP TypeScript SDK has a ReDoS vulnerabilityGHSA-w48q-cv73-mx4w Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by defaultGHSA-cvhv-6xm6-c3v4 Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handlerGHSA-r7x9-8ph7-w8cg Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email RoutingGHSA-w5cr-2qhr-jqc5 Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground siteGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-wqch-xfxh-vrr4 body-parser is vulnerable to denial of service when url encoding is usedGHSA-737v-mqg7-c878 defu: Prototype pollution via `__proto__` key in defaults argumentGHSA-cfw5-2vxh-hr84 devalue has prototype pollution in devalue.parse and devalue.unflattenGHSA-vj54-72f3-p5jv devalue prototype pollution vulnerabilityGHSA-33vc-wfww-vjfv jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBeginGHSA-4fh9-h7wg-q85m mdast-util-to-hast has unsanitized class attributeGHSA-28wg-ghj8-5hjv nanoid: non-secure generators can loop indefinitely with negative sizeGHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroGHSA-28wg-ghj8-5hjv nanoid: non-secure generators can loop indefinitely with negative sizeGHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroGHSA-27v5-c462-wpq7 path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcardsGHSA-j3q9-mxjg-w52f path-to-regexp vulnerable to Denial of Service via sequential optional groupsGHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob MatchingGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-6g55-p6wh-862q PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.