Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2026-53512 Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsGHSA-xg6x-h9c9-2m83 Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)CVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2025-55182 next: React Server Components: Pre-authentication remote code execution via unsafe deserializationCVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansionCVE-2026-3125 opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypassCVE-2025-61928 Better Auth: Unauthenticated API key creation through api-key pluginCVE-2026-45364 Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotationCVE-2026-53514 Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization pluginCVE-2026-53516 Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered emailCVE-2026-53518 @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitiveGHSA-86j7-9j95-vpqj Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcpGHSA-9h47-pqcx-hjr4 Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by defaultGHSA-qq9h-g4jm-xgf3 Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-inGHSA-x732-6j76-qmhm Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate LimitsGHSA-wxw3-q3m9-c3jr Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCECVE-2025-13466 body-parser: body-parser denial of serviceCVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexityCVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionCVE-2026-69152 brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arraysCVE-2026-33750 brace-expansion: brace-expansion: Denial of Service via zero step value in brace patternCVE-2026-35209 defu: Prototype pollution via `__proto__` key in defaults argumentCVE-2026-39356 Drizzle ORM has SQL injection via improperly escaped SQL identifiersCVE-2026-26278 fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-pw9m-5jxm-xr6h Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsGHSA-xg6x-h9c9-2m83 Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)GHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesGHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesGHSA-9qr9-h5gf-34mp Next.js is vulnerable to RCE in React flight protocolGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-7h2j-956f-4vf2 @isaacs/brace-expansion has Uncontrolled Resource ConsumptionGHSA-c7mq-gh6q-6q7c opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypassGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-7w99-5wm4-3g79 @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitiveGHSA-86j7-9j95-vpqj Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcpGHSA-99h5-pjcv-gr6v Better Auth: Unauthenticated API key creation through api-key pluginGHSA-9h47-pqcx-hjr4 Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by defaultGHSA-fmh4-wcc4-5jm3 Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization pluginGHSA-g38m-r43w-p2q7 Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered emailGHSA-p6v2-xcpg-h6xw Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotationGHSA-qq9h-g4jm-xgf3 Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-inGHSA-wxw3-q3m9-c3jr Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCEGHSA-x732-6j76-qmhm Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate LimitsGHSA-wqch-xfxh-vrr4 body-parser is vulnerable to denial of service when url encoding is usedGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.