Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.grafana-api-key Identified a Grafana API key, which could compromise monitoring dashboards and sensitive data analytics.curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.grafana-api-key Identified a Grafana API key, which could compromise monitoring dashboards and sensitive data analytics.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.Packages you depend on that have known security holes (CVEs).
CVE-2023-45133 babel: arbitrary code executionCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2026-33937 handlebars.js: Handlebars: Remote Code Execution via crafted Abstract Syntax Tree object in compile()CVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2026-34601 xmldom: xmldom: XML structure injection via CDATA terminatorCVE-2026-41672 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...CVE-2026-41673 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...CVE-2026-41674 xmldom: xmldom: Arbitrary XML markup injectionCVE-2026-41675 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...CVE-2026-45149 brace-expansion: Large numeric range defeats documented `max` DoS protectionCVE-2026-41238 DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollutionCVE-2026-41239 DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressionsCVE-2026-41240 DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitizationGHSA-39q2-94rc-95cp DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluationCVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template importsCVE-2026-2950 lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypassCVE-2026-41148 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...CVE-2026-41149 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...CVE-2026-41150 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...CVE-2026-41159 Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...CVE-2026-27903 minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patternsCVE-2026-27904 minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressionsCVE-2026-44573 Next.js has a Middleware / Proxy bypass in Pages Router applications using i18nCVE-2026-44574 Next.js has a Middleware / Proxy bypass through dynamic route parameter injectionCVE-2026-44575 Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routesYour dependencies cross-checked against the OSV vulnerability database.
RUSTSEC-2021-0122 Generated code can read and write out of bounds in safe codeGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeRUSTSEC-2021-0122 Generated code can read and write out of bounds in safe codeRUSTSEC-2019-0036 Type confusion if __private_get_type_id__ is overriddenGHSA-g93w-mfhg-p222 Angular vulnerable to XSS in i18n attribute bindingsGHSA-g93w-mfhg-p222 Angular vulnerable to XSS in i18n attribute bindingsGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type ConfusionGHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype PollutionGHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype PollutionGHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype PollutionGHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype PollutionGHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-35jp-ww65-95wh axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`GHSA-3g43-6gmg-66jw axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeGHSA-3p68-rc4w-qgx5 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRFGHSA-3w6x-2g7m-8v23 Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`GHSA-43fc-jf86-j433 Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfigGHSA-445q-vr5w-6q77 Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamGHSA-4hjh-wcwx-xvwj Axios is vulnerable to DoS attack through lack of data size checkGHSA-5c9x-8gcm-mpgx Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0GHSA-62hf-57xw-28j9 Axios: unbounded recursion in toFormData causes DoS via deeply nested request dataGHSA-6chq-wfr3-2hj9 Axios: Header Injection via Prototype PollutionGHSA-898c-q2cr-xwhg axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functionsGHSA-fvcv-3m26-pcqx Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.