Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-31808 file-type: file-type: Denial of Service due to infinite loop in ASF file parsingCVE-2026-13311 shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsingCVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsCVE-2026-45736 ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`Your dependencies cross-checked against the OSV vulnerability database.
GHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-92pp-h63x-v22m @hono/node-server: Middleware bypass via repeated slashes in serveStaticGHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawnGHSA-5v7r-6r5c-r473 file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-headerGHSA-26pp-8wgv-hjvm Hono missing validation of cookie name on write path in setCookie()GHSA-2gcr-mfcq-wcc3 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsGHSA-3hrh-pfw6-9m5x Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionGHSA-458j-xx4x-4375 hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSRGHSA-54fx-42gc-7vw4 Hono: Algorithmic Complexity DoS in Language MiddlewareGHSA-69xw-7hcm-h432 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionGHSA-88fw-hqm2-52qc hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardGHSA-8j4g-w8fx-2239 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersGHSA-9vqf-7f2p-gf9v Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsGHSA-f23p-vx2j-j53r Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureGHSA-f577-qrjj-4474 Hono: JWT middleware accepts any Authorization scheme, not only BearerGHSA-hvrm-45r6-mjfj hono/jsx does not isolate context per request, leading to cross-request data disclosureGHSA-j6c9-x7qj-28xf hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeGHSA-p77w-8qqv-26rm Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageGHSA-qp7p-654g-cw7p Hono has CSS Declaration Injection via Style Object Values in JSX SSRGHSA-r5rp-j6wh-rvv4 Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()GHSA-rv63-4mwf-qqc2 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`GHSA-w62v-xxxg-mg59 Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityGHSA-wgpf-jwqj-8h8p hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restGHSA-wmmm-f939-6g9c Hono: Middleware bypass via repeated slashes in serveStaticCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.