Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesCVE-2021-44906 minimist: prototype pollutionCVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template functionCVE-2022-0686 npm-url-parse: Authorization bypass through user-controlled keyCVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate functionCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate functionCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate functionCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2021-3377 nodejs-ansi_up: XSS due to insufficient URL sanitizationCVE-2020-7760 codemirror: ReDoS in tokenBase function in javascript.jsCVE-2020-7760 codemirror: ReDoS in tokenBase function in javascript.jsCVE-2020-11022 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter methodCVE-2020-11023 jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methodsCVE-2021-41182 jquery-ui: XSS in the altField option of the datepicker widgetCVE-2021-41183 jquery-ui: XSS in *Text options of the datepicker widgetCVE-2021-41184 jquery-ui: XSS in the 'of' option of the .position() utilCVE-2022-31160 jqueryui: XSS when refreshing a checkboxradio with an HTML-like initial text labelCVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep functionCVE-2021-23337 nodejs-lodash: command injection via templateCVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template importsCVE-2020-28500 nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functionsCVE-2025-13465 lodash: prototype pollution in _.unset and _.omit functionsYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions priorCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.