Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-3660 A arbitrary code injection vulnerability in TensorFlow's Keras framewo ...CVE-2025-12060 keras: Keras Path Traversal VulnerabilityCVE-2025-9906 keras: Arbitrary Code execution in Keras Safe ModeCVE-2026-1462 keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe ModeCVE-2025-12058 keras: Keras Model.load_model Arbitrary Local File Loading and SSRFYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-1486 Keras Directory Traversal VulnerabilityPYSEC-2026-369 Keras code injection vulnerabilityPYSEC-2026-1486 Keras Directory Traversal VulnerabilityPYSEC-2026-369 Keras code injection vulnerabilityPYSEC-2026-457 Arbitrary Code Execution in PillowPYSEC-2025-121 An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.PYSEC-2026-1487 Keras is vulnerable to arbitrary local file loading and Server-Side Request ForgeryPYSEC-2026-2324 Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filtPYSEC-2026-2547 Keras has an untrusted deserialization vulnerabilityGHSA-26c4-7vv6-867j Keras: HDF5 virtual datasets can disclose local filesGHSA-36fq-jgmw-4r9c Keras is vulnerable to Deserialization of Untrusted DataGHSA-5gwj-m78q-7pq3 Keras: Lambda deserialization can bypass safe mode and execute codeGHSA-gh82-f9x8-5frx Keras: DiskIOStore permits path traversal through crafted layer namesGHSA-m8wh-29wm-52mv Keras: HDF5 links can disclose local file contentsGHSA-v2w2-w228-c444 Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle dataPYSEC-2017-74 The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.PYSEC-2025-121 An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.PYSEC-2026-1487 Keras is vulnerable to arbitrary local file loading and Server-Side Request ForgeryPYSEC-2026-2324 Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filtPYSEC-2026-2547 Keras has an untrusted deserialization vulnerabilityGHSA-26c4-7vv6-867j Keras: HDF5 virtual datasets can disclose local filesGHSA-36fq-jgmw-4r9c Keras is vulnerable to Deserialization of Untrusted DataGHSA-5gwj-m78q-7pq3 Keras: Lambda deserialization can bypass safe mode and execute codeGHSA-gh82-f9x8-5frx Keras: DiskIOStore permits path traversal through crafted layer namesGHSA-m8wh-29wm-52mv Keras: HDF5 links can disclose local file contentsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-pypi-code-execution code-execution match in psutil 7.2.2guarddog-pypi-code-execution code-execution match in matplotlib 2.2.2guarddog-pypi-shady-links shady-links match in tqdm 4.70.0A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.