Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
discord-client-secret Discovered a potential Discord client secret, risking compromised Discord bot integrations and data leaks.Packages you depend on that have known security holes (CVEs).
CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket framesCVE-2026-15157 undici: undici: HTTP header injection via unvalidated blob-like body type propertyCVE-2026-16728 undici: undici: Response desynchronization via retry interceptor with mismatched Content-LengthCVE-2026-16729 undici: Undici: Cookie attribute injection allows bypassing security protectionsCVE-2026-9679 undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingCVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsCVE-2026-45736 ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`CVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie headerCVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.Your dependencies cross-checked against the OSV vulnerability database.
GHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-jfgx-wxx8-mp94 Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hostsGHSA-q6x5-8v7m-xcrf protobufjs has overlong UTF-8 decodingGHSA-6v7q-wjvx-w8wg basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD CommandsGHSA-chqc-8p9q-pq6q basic-ftp has FTP Command Injection via CRLFGHSA-rp42-5vxx-qpwr basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()GHSA-rpmf-866q-6p89 basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response bufferingGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-jxxr-4gwj-5jf2 brace-expansion: Large numeric range defeats documented `max` DoS protectionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-jmr9-qjv8-65gv extract-zip unvalidated symlink path traversalGHSA-4c8g-83qw-93j6 fast-uri vulnerable to host confusion via failed IDN canonicalizationGHSA-7p8r-x3mc-p8w7 fast-uri vulnerable to host confusion via backslash authority introducerGHSA-q3j6-qgpj-74h6 fast-uri vulnerable to path traversal via percent-encoded dot segmentsGHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-v39h-62p7-jpjc fast-uri vulnerable to host confusion via percent-encoded authority delimitersGHSA-5wm8-gmm8-39j9 fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributesGHSA-gh4j-gqv2-49f6 fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped DelimitersGHSA-mwp4-54f8-5fhr ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypassGHSA-v2v4-37r5-5v8g ip-address has XSS in Address6 HTML-emitting methodsGHSA-28wg-ghj8-5hjv nanoid: non-secure generators can loop indefinitely with negative sizeGHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroGHSA-6g55-p6wh-862q PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.