Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-51736 CVE-2024-51736: Command execution hijack on Windows with Process classCVE-2023-45133 babel: arbitrary code executionCVE-2023-28154 webpack: avoid cross-realm objectsCVE-2023-45133 babel: arbitrary code executionCVE-2023-28154 webpack: avoid cross-realm objectsCVE-2023-40033 Flarum vulnerable to LFI and Blind SSRF via Avatar uploadCVE-2023-22488 Flarum notifications can leak restricted contentCVE-2023-27577 Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server filesCVE-2024-21641 Flarum's logout Route allows open redirectsCVE-2025-27794 Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie OverwriteCVE-2026-41887 Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)CVE-2022-24775 guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8 ...CVE-2023-29197 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2026-48998 guzzlehttp/psr7: guzzlehttp/psr7: Information disclosure via improper Host header validationCVE-2026-49214 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2026-55766 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2026-59882 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2023-29530 HTTP Multiline Header TerminationCVE-2022-31109 Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack.CVE-2026-71488 league/commonmark is a PHP library for parsing and rendering CommonMar ...GHSA-c2pc-g5qf-rfrf league/commonmark's quadratic complexity bugs may lead to a denial of serviceGHSA-g2gp-3wwq-f4ph league/commonmark: Denial of service via adjacent inline attribute blocksGHSA-jfm3-95jq-q3rf league/commonmark: Denial of service via duplicate footnote definitionsCVE-2025-46734 league/commonmark is a PHP Markdown parser. A cross-site scripting (XS ...CVE-2026-71478 league/commonmark is a PHP library for parsing and rendering CommonMar ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-hc6q-2mpp-qw7j Cross-realm object access in Webpack 5GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-hc6q-2mpp-qw7j Cross-realm object access in Webpack 5GHSA-67c6-q4j4-hccg Flarum vulnerable to LFI and Blind SSRF via Avatar uploadGHSA-733r-8xcp-w9mr Flarum's logout Route allows open redirectsGHSA-8gcg-vwmw-rxj4 Flarum notifications can leak restricted contentGHSA-hg9j-64wp-m9px Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie OverwriteGHSA-vhm8-wwrf-3gcw Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server filesGHSA-xjvc-pw2r-6878 Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)GHSA-34xg-wgjx-8xph guzzlehttp/psr7 has Host Confusion via Authority ReinterpretationGHSA-c2w2-prh8-qm98 guzzlehttp/psr7: Host Confusion via Weak URI Host ValidationGHSA-hq7v-mx3g-29hw guzzlehttp/psr7 has CRLF Injection via URI Host ComponentGHSA-q7rv-6hp3-vh96 Improper Input Validation in guzzlehttp/psr7GHSA-vm85-hxw5-5432 guzzlehttp/psr7: CRLF Injection in HTTP Start-Line SerializationGHSA-wxmh-65f7-jcvw Improper header name validation in guzzlehttp/psr7GHSA-8274-h5jp-97vr Diactoros before 2.11.1 vulnerable to HTTP Host Header AttackGHSA-xv3h-4844-9h36 HTTP Multiline Header TerminationGHSA-29pj-957v-52mc league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytesGHSA-2q4p-g7hv-5rgv league/commonmark: Quadratic-time denial of service when parsing crafted MarkdownGHSA-3527-qv2q-pfvx league/commonmark contains a XSS vulnerability in Attributes extensionGHSA-c2pc-g5qf-rfrf league/commonmark's quadratic complexity bugs may lead to a denial of serviceGHSA-g2gp-3wwq-f4ph league/commonmark: Denial of service via adjacent inline attribute blocksGHSA-jfm3-95jq-q3rf league/commonmark: Denial of service via duplicate footnote definitionsGHSA-j3f9-p6hm-5w6q Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocaleCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.