Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2021-28305 An issue was discovered in the diesel crate before 1.4.6 for Rust. The ...CVE-2020-35863 An issue was discovered in the hyper crate before 0.12.34 for Rust. HT ...CVE-2019-16138 Use after free in imageCVE-2020-25573 An issue was discovered in the linked-hash-map crate before 0.5.3 for ...CVE-2020-35866 Data races in rusqliteCVE-2020-35867 Data races in rusqliteCVE-2020-35868 Data races in rusqliteCVE-2020-35869 Mishandling of format strings in rusqliteCVE-2020-35870 Use after free in rusqliteCVE-2020-35872 Improper type usage in rusqliteCVE-2020-35873 Use after free in rusqliteCVE-2017-18589 Improper Input Validation in cookieGHSA-h5x4-m2qf-r4f2 Diesel's SQLite backend has possible UTF-8 corruptionGHSA-wq9x-qwcq-mmgf Diesel vulnerable to Binary Protocol Misinterpretation caused by Truncating or Overflowing CastsGHSA-ggxf-9f6j-w742 Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`GHSA-m9p2-fxp5-v3fp Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`GHSA-q8x8-jrhj-fh9p Diesel: Possible unaligned data access for implementations of `SqliteAggregate`GHSA-f67m-9j94-qv9j Parser creates invalid uninitialized valueCVE-2021-32714 hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper ...GHSA-f67m-9j94-qv9j Parser creates invalid uninitialized valueCVE-2021-32714 hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper ...CVE-2024-12224 idna: idna accepts Punycode labels that do not produce any non-ASCII when decodedCVE-2020-35916 An issue was discovered in the image crate before 0.23.12 for Rust. A ...CVE-2022-35737 sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C APICVE-2020-35919 An issue was discovered in the net2 crate before 0.2.36 for Rust. It h ...Your dependencies cross-checked against the OSV vulnerability database.
RUSTSEC-2021-0037 Fix a use-after-free bug in diesels Sqlite backendRUSTSEC-2019-0036 Type confusion if __private_get_type_id__ is overriddenRUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data lossRUSTSEC-2020-0008 Flaw in hyper allows request smuggling by sending a body in GET requestsRUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data lossRUSTSEC-2019-0014 Flaw in interface may drop uninitialized instance of arbitrary typesRUSTSEC-2020-0026 linked-hash-map creates uninitialized NonNull pointerRUSTSEC-2020-0014 Various memory safety issuesRUSTSEC-2020-0027 traitobject assumes the layout of fat pointersGHSA-vjrq-cg9x-rfjp Improper Input Validation in cookieRUSTSEC-2024-0365 Binary Protocol Misinterpretation caused by Truncating or Overflowing CastsRUSTSEC-2026-0111 Possible UTF-8 corruption in Diesels SQLite backendRUSTSEC-2026-0136 Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`RUSTSEC-2026-0137 Possible unaligned data access for implementations of `SqliteAggregate`RUSTSEC-2026-0172 Possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`RUSTSEC-2021-0078 Lenient `hyper` header parsing of `Content-Length` could allow request smugglingRUSTSEC-2021-0078 Lenient `hyper` header parsing of `Content-Length` could allow request smugglingRUSTSEC-2024-0421 `idna` accepts Punycode labels that do not produce any non-ASCII when decodedRUSTSEC-2020-0073 Mutable reference with immutable provenanceRUSTSEC-2022-0090 `libsqlite3-sys` via C SQLite CVE-2022-35737RUSTSEC-2020-0080 `miow` invalidly assumes the memory layout of std::net::SocketAddrRUSTSEC-2020-0078 `net2` invalidly assumes the memory layout of std::net::SocketAddrRUSTSEC-2024-0357 `MemBio::get_buf` has undefined behavior with empty buffersGHSA-xp3w-r5p5-63rr rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsRUSTSEC-2022-0013 Regexes with large repetitions on empty sub-expressions take a very long time to parseCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.