Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.Packages you depend on that have known security holes (CVEs).
CVE-2018-1000620 nodejs-cryptiles: Insecure randomness causes the randomDigits() function returns a pseudo-random data string biased to certain digitsCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesCVE-2025-14762 aws-sdk-ruby: AWS SDK for Ruby: Data integrity compromise via missing cryptographic key commitmentCVE-2024-49761 rexml: REXML ReDoS vulnerabilityCVE-2024-35176 REXML: DoS parsing an XML with many `<`s in an attribute valueCVE-2024-39908 rexml: DoS vulnerability in REXMLCVE-2024-41123 rexml: rubygem-rexml: DoS when parsing an XML having many specific characters such as whitespace character, >] and ]>CVE-2024-41946 rexml: DoS vulnerability in REXMLCVE-2024-43398 rexml: DoS vulnerability in REXMLCVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate functionCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2026-12143 form-data: form-data: Form field override via CRLF injectionCVE-2022-29167 hawk: REDoS in hawk.utils.parseHost() when parsing Host headerCVE-2019-20149 nodejs-kind-of: ctorName in index.js allows external user input to overwrite certain internal attributesCVE-2018-16487 lodash: Prototype pollution in utilities functionCVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep functionCVE-2021-23337 nodejs-lodash: command injection via templateCVE-2026-2950 lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypassCVE-2021-23490 Uncontrolled Resource Consumption in parse-link-headerCVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsingCVE-2022-25883 nodejs-semver: Regular expression denial of serviceCVE-2023-26136 tough-cookie: prototype pollution in cookie memstoreCVE-2023-26136 tough-cookie: prototype pollution in cookie memstoreYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-2xgq-q749-89fq AWS SDK for Ruby's S3 Encryption Client has a Key Commitment IssueGHSA-2rxp-v6pw-ch6m REXML ReDoS vulnerabilityGHSA-4xqq-m2hx-25v8 REXML denial of service vulnerabilityGHSA-5866-49gr-22v4 REXML DoS vulnerabilityGHSA-r55c-59qm-vjw6 REXML DoS vulnerabilityGHSA-vg3r-rm7w-2xgh REXML contains a denial of service vulnerabilityGHSA-vmwr-mc7x-5vc3 REXML denial of service vulnerabilityGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-v88g-cgmw-v5xw Prototype Pollution in AjvGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-hmw2-7cc7-3qxx form-data: CRLF injection in form-data via unescaped multipart field names and filenamesGHSA-44pw-h2cw-w3vq Uncontrolled Resource Consumption in HawkGHSA-c429-5p7v-vgjp hoek subject to prototype pollution via the clone function.GHSA-6c8f-qphg-qjgp Validation Bypass in kind-ofGHSA-35jh-r3h4-6jhm Command Injection in lodashGHSA-4xc9-xhrj-v574 Prototype Pollution in lodashGHSA-f23m-r3pf-42rh lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`GHSA-fvqr-27wr-82fm Prototype Pollution in lodashGHSA-p6mc-m468-83gw Prototype Pollution in lodashGHSA-q674-xm3x-2926 Uncontrolled Resource Consumption in parse-link-headerGHSA-6rw7-vpxm-498p qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustionGHSA-p8p7-x288-28g6 Server-Side Request Forgery in RequestGHSA-p8p7-x288-28g6 Server-Side Request Forgery in RequestCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-shady-links shady-links match in github-base 0.5.4A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.