Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisationCVE-2021-44521 cassandra: RCE for scripted UDFsCVE-2015-6420 Insecure Deserialization in Apache Commons CollectionCVE-2025-23015 org.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actionsCVE-2012-6612 Solr: XML eXternal Entity (XXE) flaw in XML and XSLT UpdateRequestHandlerCVE-2017-3163 solr: Directory traversal via Index Replication HTTP APICVE-2017-3164 Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (in ...CVE-2018-1308 Solr: XML external entity expansion in handler/dataimport/DataImporter.java allows remote attackers to read arbitrary filesCVE-2019-0193 solr: Remote Code Execution via DataImportHandlerCVE-2019-12401 solr: XML resource consumption attack via update handlerCVE-2021-29262 solr: misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settingsCVE-2025-24814 solr: org.apache.solr: Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted filesCVE-2013-6397 Solr: directory traversal when loading XSL stylesheets and Velocity templatesCVE-2013-6407 Solr: XML eXternal Entity (XXE) flaw in XML and XSLT UpdateRequestHandlerCVE-2013-6408 Solr: XML eXternal Entity (XXE) flaw in DocumentAnalysisRequestHandlerCVE-2015-8795 Improper Neutralization of Input During Web Page Generation in Apache SolrCVE-2015-8797 Improper Neutralization of Input During Web Page Generation in Apache SolrCVE-2018-11802 solr: Information disclosure via Rule-base Authorization pluginYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.