Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2023-45311 Code injection in fseventsCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2023-26464 log4j1-socketappender: DoS via hashmap loggingCVE-2018-3258 mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018)CVE-2019-2692 mysql-connector-java: privilege escalation in MySQL connectorCVE-2021-2471 mysql-connector-java: unauthorized access to criticalCVE-2022-21363 mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL ConnectorsCVE-2019-9142 Moderate severity vulnerability that affects org.b3log:symphonyCVE-2022-29631 Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vul ...CVE-2021-37714 jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuckCVE-2022-36033 jsoup: The jsoup cleaner may incorrectly sanitize crafted XSS attempts if SafeList.preserveRelativeLinks is enabledCVE-2017-18640 snakeyaml: Billion laughs attack via alias featureCVE-2022-1471 SnakeYaml: Constructor Deserialization Remote Code ExecutionCVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collectionsCVE-2022-38749 snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNodeCVE-2022-38750 snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObjectCVE-2022-38751 snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.matchCVE-2022-38752 snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCodeCVE-2022-41854 dev-java/snakeyaml: DoS via stack overflowCVE-2020-7788 nodejs-ini: Prototype pollution via malicious INI fileCVE-2022-25883 nodejs-semver: Regular expression denial of serviceCVE-2021-32803 nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwriteCVE-2021-32804 nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwriteYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-fhjf-83wg-r2j9 Prototype Pollution in mixin-deepGHSA-4g88-fppr-53pp Prototype Pollution in set-valueGHSA-4g88-fppr-53pp Prototype Pollution in set-valueGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-fhjf-83wg-r2j9 Prototype Pollution in mixin-deepGHSA-4g88-fppr-53pp Prototype Pollution in set-valueGHSA-4g88-fppr-53pp Prototype Pollution in set-valueGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.