Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2019-20477 PyYAML: command execution through python/object/apply constructor in FullLoaderCVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747CVE-2020-1747 PyYAML: arbitrary command execution through python/object/new when FullLoader is usedCVE-2026-54906 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of serviceCVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code executionCVE-2021-28834 rubygem-kramdown: allows arbitrary classes to be instantiatedCVE-2020-11538 python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2CVE-2020-5310 python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecodeCVE-2020-5311 python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.cCVE-2020-5312 python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.cCVE-2021-25289 python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.cCVE-2021-34552 python-pillow: Buffer overflow in image convert functionCVE-2022-22817 python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressionsCVE-2023-50447 pillow: Arbitrary Code Execution via the environment parameterCVE-2021-23792 The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 ar ...CVE-2021-32740 rubygem-addressable: ReDoS in templatesCVE-2026-35611 addressable: Addressable: Denial of Service via crafted URI templatesCVE-2026-54904 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#updateCVE-2026-54905 concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusionCVE-2020-26298 rubygem-redcarpet: does not escape HTML when processing quotes which could result in XSS vulnerabilityCVE-2022-31163 rubygem-tzinfo: arbitrary code executionCVE-2019-16865 python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of serviceCVE-2019-19911 python-pillow: uncontrolled resource consumption in FpxImagePlugin.pyCVE-2020-10177 python-pillow: multiple out-of-bounds reads in libImaging/FliDecode.cCVE-2020-10378 python-pillow: an out-of-bounds read in libImaging/PcxDecode.c can occur when reading PCX filesYour dependencies cross-checked against the OSV vulnerability database.
GHSA-52p9-v744-mwjj Remote code execution in KramdownGHSA-mqm2-cgpr-p4m6 Unintended read access in kramdown gemGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityGHSA-jfh8-c2jp-5v3q Remote code injection in Log4jGHSA-7rjr-3q55-vv33 Incomplete fix for Apache Log4j vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.