Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2020-7769 This affects the package nodemailer before 6.4.16. Use of crafted reci ...CVE-2025-14874 nodemailer: Nodemailer: Denial of service via crafted email address headerGHSA-p6gq-j5cr-w38f Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered messageCVE-2021-23400 The package nodemailer before 6.6.1 are vulnerable to HTTP Header Inje ...CVE-2025-13033 nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation ConflictGHSA-268h-hp4c-crq3 Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injectionGHSA-9h6g-pr28-7cqp nodemailer ReDoS when trying to send a specially crafted emailGHSA-r7g4-qg5f-qqm2 Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential InterceptionGHSA-vvjj-xcjg-gr5g Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO) GHSA-wqvq-jvpq-h66f Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalizationGHSA-c7w3-x93f-qmm8 Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameterYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type ConfusionGHSA-765h-qjxv-5f44 Prototype Pollution in handlebarsGHSA-f2jv-r9rf-7988 Remote code execution in handlebars when compiling templatesGHSA-w457-6q6x-cgp9 Prototype Pollution in handlebarsGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-48ww-j4fc-435p Command injection in nodemailerGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-v88g-cgmw-v5xw Prototype Pollution in AjvGHSA-93q8-gq69-wqmw Inefficient Regular Expression Complexity in chalk/ansi-regexGHSA-fwr7-v2mv-hh25 Prototype Pollution in asyncGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawnGHSA-h6ch-v84p-w6p9 Regular Expression Denial of Service (ReDoS)GHSA-2cf5-4w76-r9qv Arbitrary Code Execution in handlebarsGHSA-2qvq-rjwj-gvw9 Handlebars.js has Prototype Pollution Leading to XSS through Partial Template InjectionGHSA-3cqr-58rm-57f8 Arbitrary Code Execution in HandlebarsGHSA-3mfm-83xf-c92r Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-blockGHSA-62gr-4qp9-h98f Regular Expression Denial of Service in HandlebarsGHSA-9cx6-37pm-9jff Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template CompilationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-shady-links shady-links match in nodemailer 4.7.0A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.