Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-gcfj-64vw-6mp9 Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningCVE-2026-67314 axios: axios: Outbound Request Tampering via Prototype Pollution in Basic AuthGHSA-42h9-826w-cgv3 Axios: Excessive recursion in formDataToJSON can cause denial of serviceGHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype valuesGHSA-f4gw-2p7v-4548 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosGHSA-hcpx-6fm6-wx23 Axios form serializer maxDepth bypass via {} metatokenGHSA-jqh4-m9w3-8hp9 Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`GHSA-mmx7-hfxf-jppx Axios: Prototype pollution gadgets can alter axios request constructionGHSA-mwf2-3pr3-8698 Axios: HTTP/2 streamed uploads bypass `maxBodyLength`GHSA-pmv8-rq9r-6j72 Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceCVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalizationCVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-18446 fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authorityCVE-2026-12143 form-data: form-data: Form field override via CRLF injectionCVE-2026-54290 hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardCVE-2026-54286 hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-54287 hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeCVE-2026-54288 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`CVE-2026-54289 hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restCVE-2026-59895 hono: Hono: Arbitrary markup injection via improper handling of class names in server-side rendering.CVE-2026-59896 hono: Hono: Information disclosure due to improper context isolation in server-side renderingCVE-2026-59897 hono: Hono: Information disclosure due to incorrect header de-duplication in AWS API Gateway v1 adapterCVE-2026-69207 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersCVE-2026-71848 Hono: Algorithmic Complexity DoS in Language MiddlewareYour dependencies cross-checked against the OSV vulnerability database.
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-42h9-826w-cgv3 Axios: Excessive recursion in formDataToJSON can cause denial of serviceGHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype valuesGHSA-f4gw-2p7v-4548 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosGHSA-gcfj-64vw-6mp9 Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningGHSA-hcpx-6fm6-wx23 Axios form serializer maxDepth bypass via {} metatokenGHSA-jqh4-m9w3-8hp9 Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`GHSA-mmx7-hfxf-jppx Axios: Prototype pollution gadgets can alter axios request constructionGHSA-mwf2-3pr3-8698 Axios: HTTP/2 streamed uploads bypass `maxBodyLength`GHSA-pmv8-rq9r-6j72 Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceGHSA-xj6q-8x83-jv6g Axios: Prototype pollution auth subfields can inject Basic authGHSA-4c8g-83qw-93j6 fast-uri vulnerable to host confusion via failed IDN canonicalizationGHSA-7p8r-x3mc-p8w7 fast-uri vulnerable to host confusion via backslash authority introducerGHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-hmw2-7cc7-3qxx form-data: CRLF injection in form-data via unescaped multipart field names and filenamesGHSA-54fx-42gc-7vw4 Hono: Algorithmic Complexity DoS in Language MiddlewareGHSA-88fw-hqm2-52qc hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardGHSA-8j4g-w8fx-2239 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersGHSA-f23p-vx2j-j53r Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureGHSA-hvrm-45r6-mjfj hono/jsx does not isolate context per request, leading to cross-request data disclosureGHSA-j6c9-x7qj-28xf hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeGHSA-rv63-4mwf-qqc2 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`GHSA-w62v-xxxg-mg59 Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityGHSA-wgpf-jwqj-8h8p hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restGHSA-wwfh-h76j-fc44 hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.