Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2025-61686 react-router: React Router has Path Traversal in File Session StorageCVE-2025-59057 react-router: @remix-run/router: React Router XSS VulnerabilityCVE-2026-21884 react-router: @remix-run/react: React Router SSR XSS in ScrollRestorationCVE-2026-22029 @remix-run/router: react-router: React Router vulnerable to XSS via Open RedirectsCVE-2026-40181 react-router: React Router: Open redirect vulnerability via specially crafted URLsCVE-2026-22030 react-router: React Router CSRF in Action/Server Action Request ProcessingCVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexityCVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionCVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationCVE-2026-65898 DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when ...GHSA-55q2-fjhq-7xh7 DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSSCVE-2026-12143 form-data: form-data: Form field override via CRLF injectionCVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documentsGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedCVE-2026-48801 linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerabilityCVE-2026-59887 linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker textCVE-2026-2327 markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify functionCVE-2026-48988 markdown-it is a Markdown parser. Versions 14.1.1 and below contain a ...CVE-2026-50159 mermaid: Mermaid: CSS injection allows altering page elements via diagram inputCVE-2026-71436 mermaid: Mermaid XY Charts: Denial of Service via invalid X-Axis parametersCVE-2026-71437 mermaid: Mermaid: Prototype pollution vulnerability allows potential arbitrary code executionCVE-2026-71439 mermaid: Mermaid: Denial of Service via Radar Diagrams 'ticks' parameterCVE-2026-67213 nanoid: nanoid: Denial of Service via infinite loop in random ID generationCVE-2026-67214 nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...CVE-2024-55565 nanoid: nanoid mishandles non-integer valuesYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-457 Arbitrary Code Execution in PillowGHSA-9583-h5hc-x8cw React Router has Path Traversal in File Session StorageGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedPYSEC-2026-457 Arbitrary Code Execution in PillowPYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions priorPYSEC-2026-1691 nbconvert has an uncontrolled search path that leads to unauthorized code execution on WindowsPYSEC-2026-2229 The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intendePYSEC-2026-2230 The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdPYSEC-2023-227 An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of PYSEC-2026-165 Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer PYSEC-2026-1793 Pillow buffer overflow vulnerabilityPYSEC-2026-1794 libwebp: OOB write in BuildHuffmanTablePYSEC-2026-2253 Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without callingPYSEC-2026-2254 Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decPYSEC-2026-2255 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() witPYSEC-2026-2256 Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompressPYSEC-2026-2257 Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the PYSEC-2026-2874 Pillow has a PDF Parsing Trailer Infinite Loop (DoS)PYSEC-2026-3451 Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in IPYSEC-2026-3453 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whoPYSEC-2026-3454 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFiltePYSEC-2026-3493 Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)PYSEC-2026-3494 Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.