Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2025-8916 org.bouncycastle: BouncyCastle denial of serviceCVE-2026-5588 bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as validCVE-2023-33202 bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser classCVE-2024-29857 org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of ServiceCVE-2024-30171 bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)CVE-2024-34447 org.bouncycastle: Use of Incorrectly-Resolved Name or ReferenceYour dependencies cross-checked against the OSV vulnerability database.
GHSA-5j33-cvvr-w245 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityGHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly appliedGHSA-83qj-6fr2-vhqg Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTGHSA-fpj8-gq4v-p354 Apache Tomcat - Client certificate verification bypassGHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown userGHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validatedGHSA-vfww-5hm6-hx2j Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control SequencesGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS ConditionGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-3pjw-73gf-8qr5 jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategyGHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiationGHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)GHSA-wxr5-93ph-8wr9 Apache Commons Improper Access Control vulnerabilityGHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-pq2g-wx69-c263 Netplex Json-smart Uncontrolled Recursion vulnerabilityGHSA-23hv-mwm6-g8jf Apache Tomcat Session Fixation vulnerabilityGHSA-25xr-qj8w-c4vf Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streamsGHSA-27hp-xhwr-wr2m Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityGHSA-3p2h-wqq4-wf4h Apache Tomcat Denial of Service via invalid HTTP priority headerGHSA-42wg-hm62-jcwg Apache Tomcat installer for Windows has an untrusted search path vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.