Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
GHSA-gcfj-64vw-6mp9 Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningCVE-2026-67314 axios: axios: Outbound Request Tampering via Prototype Pollution in Basic AuthGHSA-42h9-826w-cgv3 Axios: Excessive recursion in formDataToJSON can cause denial of serviceGHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype valuesGHSA-f4gw-2p7v-4548 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosGHSA-hcpx-6fm6-wx23 Axios form serializer maxDepth bypass via {} metatokenGHSA-jqh4-m9w3-8hp9 Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`GHSA-mmx7-hfxf-jppx Axios: Prototype pollution gadgets can alter axios request constructionGHSA-mwf2-3pr3-8698 Axios: HTTP/2 streamed uploads bypass `maxBodyLength`GHSA-pmv8-rq9r-6j72 Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceCVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexityCVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionCVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationCVE-2026-45149 brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric rangesCVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documentsGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedCVE-2026-53550 js-yaml: js-yaml: Denial of Service via crafted YAML merge keysCVE-2026-48988 markdown-it is a Markdown parser. Versions 14.1.1 and below contain a ...CVE-2026-67213 nanoid: nanoid: Denial of Service via infinite loop in random ID generationCVE-2026-67214 nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...CVE-2026-67213 nanoid: nanoid: Denial of Service via infinite loop in random ID generationCVE-2026-73646 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureCVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURLCVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURLCVE-2026-22028 preact: Preact: Arbitrary script execution via JSON serialization protection bypassYour dependencies cross-checked against the OSV vulnerability database.
GHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-42h9-826w-cgv3 Axios: Excessive recursion in formDataToJSON can cause denial of serviceGHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype valuesGHSA-f4gw-2p7v-4548 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosGHSA-gcfj-64vw-6mp9 Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningGHSA-hcpx-6fm6-wx23 Axios form serializer maxDepth bypass via {} metatokenGHSA-jqh4-m9w3-8hp9 Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`GHSA-mmx7-hfxf-jppx Axios: Prototype pollution gadgets can alter axios request constructionGHSA-mwf2-3pr3-8698 Axios: HTTP/2 streamed uploads bypass `maxBodyLength`GHSA-pmv8-rq9r-6j72 Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceGHSA-xj6q-8x83-jv6g Axios: Prototype pollution auth subfields can inject Basic authGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-jxxr-4gwj-5jf2 brace-expansion: Large numeric range defeats documented `max` DoS protectionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phaseGHSA-rf6f-7fwh-wjgh Prototype Pollution via parse() in NodeJS flattedGHSA-qjx8-664m-686j JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injectionGHSA-52cp-r559-cp3m js-yaml: YAML merge-key chains can force quadratic CPU consumptionGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.