Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-67mh-4wv8-2f99 esbuild enables any website to send any requests to the development server and read the responseCVE-2023-37478 pnpm incorrectly parses tar archives relative to specificationCVE-2025-69262 pnpm: pnpm: Remote code execution via command injection in tokenHelper environment variable substitutionCVE-2025-69263 pnpm: pnpm Lockfile Integrity BypassCVE-2026-50015 pnpm: pnpm: Arbitrary file write/delete due to lack of path validation in patch filesCVE-2026-50016 pnpm: pnpm: Arbitrary code execution due to path traversal in dependency aliasesCVE-2026-55487 pnpm: pnpm: Supply chain compromise via manipulated package source stringsCVE-2026-55697 pnpm: pnpm: Arbitrary code execution via improper handling of config dependenciesCVE-2026-55698 pnpm: pnpm: Arbitrary code execution via malicious package-manager lockfileGHSA-72r4-9c5j-mj57 pnpm: `patch-remove` could delete project-selected files outside the patches directoryGHSA-fr4h-3cph-29xv pnpm: Hoisted install imports lockfile alias outside node_modulesGHSA-qrv3-253h-g69c pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configCVE-2024-47829 pnpm: pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwritingCVE-2024-53866 pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasionCVE-2026-23888 pnpm: pnpm: Arbitrary file write via path traversal in binary fetcher leading to remote code executionCVE-2026-23889 pnpm: pnpm: Arbitrary file write via path traversal on WindowsCVE-2026-23890 pnpm: pnpm: Arbitrary code execution via path traversal in bin linkingCVE-2026-24056 pnpm: pnpm symlink traversal in file:/git dependenciesCVE-2026-24131 pnpm: pnpm: Arbitrary file permission modification via directory traversalCVE-2026-48995 pnpm: pnpm: Supply chain compromise from unverified dependenciesCVE-2026-50014 pnpm: pnpm: Arbitrary Code Execution via Malicious LockfileCVE-2026-50017 pnpm: pnpm: Information disclosure of authentication credentials via malicious .npmrc fileCVE-2026-50021 pnpm: pnpm: Integrity bypass allows installation of altered packages via modified lockfileCVE-2026-50573 pnpm: pnpm: Package integrity check bypass allows installation of malicious contentCVE-2026-55180 pnpm: pacquet: pnpm and pacquet: Information disclosure of environment secrets via improper environment variable expansionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-xv26-6w52-cph6 websocket-driver: Message corruption via abuse of protocol length headersGHSA-67mh-4wv8-2f99 esbuild enables any website to send any requests to the development server and read the responseGHSA-2phv-j68v-wwqx pnpm vulnerable to Command Injection via environment variable substitutionGHSA-3qhv-2rgh-x77r pnpm: Repository config can expand victim environment secrets into registry requests before scripts runGHSA-4gxm-v5v7-fqc4 pnpm: Reserved bin name deletes PNPM_HOME during global removeGHSA-54hh-g5mx-jqcp pnpm: Unsafe default behavior breaks integrity checkGHSA-5r98-f33j-g8h7 pnpm incorrectly parses tar archives relative to specificationGHSA-5wx6-mg75-v57r pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycleGHSA-6pfh-p556-v868 pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)GHSA-6x96-7vc8-cm3p pnpm has Windows-specific tarball Path TraversalGHSA-72r4-9c5j-mj57 pnpm: `patch-remove` could delete project-selected files outside the patches directoryGHSA-7vhp-vf5g-r2fw pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic DependenciesGHSA-8cc4-rfj6-fhg4 pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwritingGHSA-cjhr-43r9-cfmw pnpm binds unscoped user-level npm auth credentials to a repository-selected registryGHSA-fr4h-3cph-29xv pnpm: Hoisted install imports lockfile alias outside node_modulesGHSA-gj8w-mvpf-x27x pnpm: Repository-controlled configDependencies can select a pacquet native install engineGHSA-hg3w-7f8c-63hp pnpm: Tarball hash of GitHub git dependencies is not stored in lockfileGHSA-hwx4-2j3j-g496 pnpm: Transitive dependency alias path traversal allows project path override via symlink replacementGHSA-m733-5w8f-5ggw pnpm has symlink traversal in file:/git dependenciesGHSA-p4xf-rf54-rj3x pnpm: Git Fetch Argument Injection via Lockfile resolution.commitGHSA-q6j5-fjx5-2mc3 pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity FieldCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.