Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-hmw2-7cc7-3qxx form-data: CRLF injection in form-data via unescaped multipart field names and filenamesGHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob MatchingGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-gcx4-mw62-g8wm DOM Clobbering Gadget found in rollup bundled scripts that leads to XSSGHSA-mw96-cpmx-2vgc Rollup 4 has Arbitrary File Write via Path TraversalGHSA-c2qf-rxjj-qqgw semver vulnerable to Regular Expression Denial of ServiceGHSA-72xf-g2v4-qvf3 tough-cookie Prototype Pollution vulnerabilityGHSA-j8xg-fqg3-53r7 word-wrap vulnerable to Regular Expression Denial of ServiceGHSA-3h5v-q93c-6h6q ws affected by a DoS when handling a request with many HTTP headersGHSA-58qx-3vcg-4xpx ws: Uninitialized memory disclosureGHSA-96hv-2xvq-fx4p ws: Memory exhaustion DoS from tiny fragments and data chunksGHSA-4x5r-pxfx-6jf8 @babel/core: Arbitrary File Read via sourceMappingURL CommentGHSA-vpq2-c234-7xj6 @tootallnate/once vulnerable to Incorrect Control Flow ScopingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.