Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-28859 redis: Async command information disclosureCVE-2023-28858 redis: Async command information disclosureYour dependencies cross-checked against the OSV vulnerability database.
CVE-2025-49844 Redis Lua Use-After-Free may lead to remote code executionCVE-2023-41056 Redis vulnerable to integer overflow in certain payloadsCVE-2024-31228 Denial-of-service due to unbounded pattern matching in RedisCVE-2024-31449 Lua library commands may lead to stack overflow and RCE in RedisCVE-2024-46981 Redis' Lua library commands may lead to remote code executionCVE-2025-32023 Redis allows out of bounds writes in hyperloglog commands leading to RCECVE-2025-46817 Lua library commands may lead to integer overflow and potential RCECVE-2025-46818 Redis: Authenticated users can execute LUA scripts as a different userCVE-2025-46819 Redis is vulnerable to DoS via specially crafted LUA scriptsCVE-2025-48367 Redis DoS Vulnerability due to bad connection error handlingCVE-2025-67733 Valkey Affected by RESP Protocol Injection via Lua error_replyCVE-2026-21863 Malformed Valkey Cluster bus message can lead to Remote DoSPYSEC-2023-45 redis-py before 4.5.3, as used in ChatGPT and other products, leaves a connection open after canceling an async Redis command at an inopportune time (in the case of a pipeline operation), and can sendPYSEC-2023-46 redis-py through 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time (in the case of a non-pipeline operation), and can send response data to the client of an CVE-2023-41053 Redis SORT_RO may bypass ACL configurationCVE-2023-45145 Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.