Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code executionCVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfigCVE-2019-16335 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSourceCVE-2019-16942 jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.*CVE-2019-16943 jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSourceCVE-2019-17267 jackson-databind: Serialization gadgets in classes of the ehcache packageCVE-2019-17531 jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*CVE-2019-20330 jackson-databind: lacks certain net.sf.ehcache blockingCVE-2020-8840 jackson-databind: Lacks certain xbean-reflect/JNDI blockingCVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-configCVE-2020-9547 jackson-databind: Serialization gadgets in ibatis-sqlmapCVE-2020-9548 jackson-databind: Serialization gadgets in anteros-coreCVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2025-49128 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocationCVE-2019-14439 jackson-databind: Polymorphic typing issue related to logback/JNDICVE-2019-14892 jackson-databind: Serialization gadgets in classes of the commons-configuration packageCVE-2019-14893 jackson-databind: Serialization gadgets in classes of the xalan packageCVE-2020-10650 A deserialization flaw was discovered in jackson-databind through 2.9. ...CVE-2020-10672 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command executionCVE-2020-10673 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command executionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.