Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parserCVE-2024-4068 braces: fails to limit the number of characters it can handleCVE-2024-29041 express: cause malformed URLs to be evaluatedGHSA-r4q5-vmmm-2653 follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect TargetsCVE-2024-21536 http-proxy-middleware: Denial of ServiceCVE-2025-32996 http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middlewareCVE-2025-32997 http-proxy-middleware: Improper Check for Unusual or Exceptional Conditions in http-proxy-middlewareCVE-2026-55602 http-proxy-middleware: http-proxy-middleware: Unintended backend routing due to crafted Host headerCVE-2024-4067 micromatch: vulnerable to Regular Expression Denial of ServiceCVE-2024-45296 path-to-regexp: Backtracking regular expressions cause ReDoSCVE-2024-52798 path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.xCVE-2026-4867 path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parametersCVE-2026-33671 picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patternsCVE-2026-33672 picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressionsCVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsingCVE-2026-12590 body-parser: body-parser: Denial of Service via invalid limit optionCVE-2024-47764 cookie: cookie accepts cookie name, path, and domain with out of bounds charactersCVE-2024-43796 express: Improper Input Handling in Express RedirectsCVE-2026-2391 qs: qs's arrayLimit bypass in comma parsing allows denial of serviceCVE-2024-43799 send: Code Execution Vulnerability in Send LibraryCVE-2024-43800 serve-static: Improper Sanitization in serve-staticYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.PYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to disPYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rePYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLsPYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=FalsePYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system tePYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.PYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to disPYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rePYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLsPYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=FalsePYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system teGHSA-qwcr-r2fm-qrc7 body-parser vulnerable to denial of service when url encoding is enabledGHSA-grv7-fg5c-xmjg Uncontrolled resource consumption in bracesGHSA-qw6h-vgh9-j6wx express vulnerable to XSS via response.redirect()GHSA-rv95-896h-c2vc Express.js Open Redirect in malformed URLsGHSA-r4q5-vmmm-2653 follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect TargetsGHSA-4www-5p9h-95mh http-proxy-middleware can call writeBody twice because "else if" is not usedGHSA-64mm-vxmg-q3vj http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypassGHSA-9gqv-wp59-fq42 http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failedGHSA-c7qv-q95q-8v27 Denial of service in http-proxy-middlewareGHSA-952p-6rrq-rcjv Regular Expression Denial of Service (ReDoS) in micromatchGHSA-37ch-88jc-xwx2 path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parametersGHSA-rhx6-c78j-4q9w path-to-regexp contains a ReDoSGHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob MatchingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.