Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.Packages you depend on that have known security holes (CVEs).
CVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template functionCVE-2026-54466 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...CVE-2023-45133 babel: arbitrary code executionCVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2026-9277 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminatorsCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2026-48068 grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiationCVE-2026-48069 grpc-js: @grpc/grpc-js: Client or server crash via malformed compressed messageCVE-2024-37168 grps-js: allocate memory for incoming messages well above configured limitsCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesCVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parserCVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parserCVE-2024-29041 express: cause malformed URLs to be evaluatedCVE-2024-11023 Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own serverCVE-2024-45296 path-to-regexp: Backtracking regular expressions cause ReDoSCVE-2024-52798 path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.xCVE-2026-4867 path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parametersCVE-2026-44289 protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decodingCVE-2026-44290 protobufjs: protobufjs: Denial of Service via crafted schemaCVE-2026-44291 protobufjs: protobufjs: Arbitrary Code Execution via prototype pollutionCVE-2026-44293 protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptorsCVE-2026-48712 protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payloadCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesYour dependencies cross-checked against the OSV vulnerability database.
GHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-cf4h-3jhx-xvhq Arbitrary Code Execution in underscoreGHSA-xv26-6w52-cph6 websocket-driver: Message corruption via abuse of protocol length headersGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2022-3112 Malicious code in fortawesome (npm)GHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-5375-pq7m-f5r2 @grpc/grpc-js: A malformed request can cause a server crashGHSA-7v5v-9h63-cj86 @grpc/grpc-js can allocate memory for incoming messages well above configured limitsGHSA-99f4-grh7-6pcq @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crashGHSA-q6x5-8v7m-xcrf protobufjs has overlong UTF-8 decodingGHSA-qwcr-r2fm-qrc7 body-parser vulnerable to denial of service when url encoding is enabledGHSA-qwcr-r2fm-qrc7 body-parser vulnerable to denial of service when url encoding is enabledGHSA-qw6h-vgh9-j6wx express vulnerable to XSS via response.redirect()GHSA-rv95-896h-c2vc Express.js Open Redirect in malformed URLsGHSA-3wf4-68gx-mph8 Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own serverGHSA-339j-hqgx-qrrx Prototype Pollution in nedbGHSA-37ch-88jc-xwx2 path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parametersGHSA-rhx6-c78j-4q9w path-to-regexp contains a ReDoSGHSA-2pr8-phx7-x9h3 protobuf.js: Denial of service from crafted field names in generated codeGHSA-66ff-xgx4-vchm protobuf.js: Code injection through bytes field defaults in generated toObject codeGHSA-685m-2w69-288q protobuf.js: Denial of service through unbounded protobuf recursionGHSA-75px-5xx7-5xc7 protobuf.js: Code generation gadget after prototype pollutionCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.