Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2023-24163 Dromara hutool vulnerable to SQL InjectionCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYSCVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypassCVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code executionCVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processingCVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS ResolutionCVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modifiedCVE-2021-0341 okhttp: information disclosure via improperly used cryptographic functionCVE-2023-3635 okio: GzipSource class improper exception handlingCVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2020-29582 kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosureCVE-2022-24329 kotlin: Not possible to lock dependencies for Multiplatform Gradle ProjectsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-6c25-cxcc-pmc4 Dromara hutool vulnerable to SQL InjectionGHSA-3wrr-7qpf-2prh jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()GHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiationGHSA-jjjh-jjxp-wpff Uncontrolled Resource Consumption in Jackson-databindGHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)GHSA-w33c-445m-f8w7 Okio Signed to Unsigned Conversion Error vulnerabilityGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.