Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2026-45249 Apache ECharts has a cross-site scripting (XSS) vulnerabilityCVE-2026-33245 react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirectsCVE-2026-34077 react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handlingCVE-2026-42211 react-router: React Router: Remote Code Execution via prototype pollution in Framework ModeCVE-2026-42342 react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpointCVE-2026-55685 react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requestsGHSA-qwww-vcr4-c8h2 React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 ResponseCVE-2026-33244 react-router: React Router: Cross-Site Scripting (XSS) via improper HTTP Location header neutralizationCVE-2026-40181 react-router: React Router: Open redirect vulnerability via specially crafted URLsCVE-2026-53666 react-router: React Router: Information disclosure via client-side constructor executionCVE-2026-53667 react-router: React Router: Untrusted redirects due to missing protocol validationCVE-2026-53669 react-router: React Router: Open Redirect vulnerability via backslashes in navigation componentsCVE-2026-53663 react-router: @remix-run/server-runtime: React Router: Insufficient CSRF protection allows integrity impactYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.