Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket framesCVE-2026-13697 undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directivesCVE-2026-1526 undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompressionCVE-2026-1528 undici: undici: Denial of Service via crafted WebSocket frame with large lengthCVE-2026-2229 undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameterCVE-2026-14643 undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsingCVE-2026-15157 undici: undici: HTTP header injection via unvalidated blob-like body type propertyCVE-2026-1525 undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headersCVE-2026-1527 undici: Undici: HTTP header injection and request smuggling vulnerabilityCVE-2026-16728 undici: undici: Response desynchronization via retry interceptor with mismatched Content-LengthCVE-2026-16729 undici: Undici: Cookie attribute injection allows bypassing security protectionsCVE-2026-22036 undici: Undici: Denial of Service via excessive decompression stepsCVE-2026-9678 undici: Undici: Information disclosure due to improper cache-control header parsingCVE-2026-9679 undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingCVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie headerCVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.Your dependencies cross-checked against the OSV vulnerability database.
GHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-cfw5-2vxh-hr84 devalue has prototype pollution in devalue.parse and devalue.unflattenGHSA-g2pg-6438-jwpf devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parseGHSA-vw5p-8cq8-m7mv Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parseGHSA-28wg-ghj8-5hjv nanoid: non-secure generators can loop indefinitely with negative sizeGHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroGHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob MatchingGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob MatchingGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-6g55-p6wh-862q PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsGHSA-fxqj-rqcc-2cmp PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unsetGHSA-qx2v-qp2m-jg93 PostCSS has XSS via Unescaped </style> in its CSS Stringify OutputGHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureGHSA-mw96-cpmx-2vgc Rollup 4 has Arbitrary File Write via Path TraversalGHSA-6738-r8g5-qwp3 svelte vulnerable to Cross-site ScriptingGHSA-crpf-4hrx-3jrp Svelte SSR attribute spreading includes inherited properties from prototype chainGHSA-f3cj-j4f6-wq85 Svelte: SSR XSS via Insecure Promise Serialization in hydratableGHSA-f7gr-6p89-r883 Svelte affected by cross-site scripting via spread attributes in Svelte SSRGHSA-h7h7-mm68-gmrc Svelte affected by XSS in SSR `<option>` elementGHSA-m56q-vw4c-c2cp Svelte SSR does not validate dynamic element tag names in `<svelte:element>`GHSA-phwv-c562-gvmh Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`GHSA-pr6f-5x2q-rwfp Svelte SSR vulnerable to cross-site scripting via spread attributesGHSA-rcqx-6q8c-2c42 Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework StateGHSA-2mjp-6q6p-2qxm Undici has an HTTP Request/Response Smuggling issueCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.