Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-r399-636x-v7f6 LangChain serialization injection vulnerability enables secret extractionGHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phaseGHSA-rf6f-7fwh-wjgh Prototype Pollution via parse() in NodeJS flattedGHSA-3644-q5cj-c5c7 LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warningGHSA-23c5-xmqv-rm74 minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsGHSA-3ppc-4f35-3m26 minimatch has a ReDoS via repeated wildcards with non-matching literal in patternGHSA-7r86-cg39-jmmj minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsGHSA-23c5-xmqv-rm74 minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsGHSA-3ppc-4f35-3m26 minimatch has a ReDoS via repeated wildcards with non-matching literal in patternGHSA-7r86-cg39-jmmj minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-2w69-qvjg-hvjx React Router vulnerable to XSS via Open RedirectsGHSA-3cgp-3xvw-98x8 React Router has XSS VulnerabilityGHSA-8v8x-cx79-35w7 React Router SSR XSS in ScrollRestorationGHSA-mw96-cpmx-2vgc Rollup 4 has Arbitrary File Write via Path TraversalGHSA-p9ff-h696-f583 Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocketGHSA-xffm-g5w8-qvg7 @eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParserGHSA-v6h2-p8h4-qcjw brace-expansion Regular Expression Denial of Service vulnerabilityGHSA-v6h2-p8h4-qcjw brace-expansion Regular Expression Denial of Service vulnerabilityGHSA-g4jq-h2w9-997c Vite middleware may serve files starting with the same name with the public directoryGHSA-jqfw-vq24-v9c3 Vite's `server.fs` settings were not applied to HTML filesGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionCode that can be exploited — injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious — typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project — not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 3.5/10scorecard-CI-Tests CI-Tests scored 0: 0 out of 14 merged PRs checked by a CI test -- score normalized to 0scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0scorecard-SAST SAST scored 0: SAST tool is not run on all commits -- score normalized to 0scorecard-Vulnerabilities Vulnerabilities scored 0: 30 existing vulnerabilities detected