Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)CVE-2025-29927 nextjs: Authorization Bypass in Next.js MiddlewareCVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2026-2739 bn.js: bn.js: Denial of Service via calling maskn(0)CVE-2026-2739 bn.js: bn.js: Denial of Service via calling maskn(0)CVE-2026-67213 nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...CVE-2026-67214 nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...CVE-2024-55565 nanoid: nanoid mishandles non-integer valuesCVE-2024-51479 next.js: next: authorization bypass in Next.jsCVE-2026-44573 next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nCVE-2026-64645 next: Next.js: Server-Side Request Forgery vulnerabilityCVE-2024-47831 next.js: Next.js image optimization has Denial of Service conditionCVE-2025-55173 nextjs: Next.js Content Injection Vulnerability for Image OptimizationCVE-2025-57752 nextjs: Next.js Affected by Cache Key Confusion for Image Optimization API RoutesCVE-2025-57822 Next.js Improper Middleware Redirect Handling Leads to SSRFCVE-2025-59471 next: NextJS Denial of Service in Image OptimizerCVE-2026-27980 next.js: Next.js: Unbounded next/image disk cache growth can exhaust storageCVE-2026-29057 next.js: Next.js: HTTP request smuggling in rewritesCVE-2026-44577 Next.js: Next.js: Denial of Service via Image Optimization APICVE-2026-45623 postcss: PostCSS: Information disclosure and denial of service via crafted CSS inputGHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureCVE-2023-44270 PostCSS: Improper input validation in PostCSSCVE-2026-41305 postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tagsCVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURLCVE-2024-37890 nodejs-ws: denial of service when handling a request with many HTTP headersYour dependencies cross-checked against the OSV vulnerability database.
GHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)GHSA-f82v-jwr5-mffw Authorization Bypass in Next.js MiddlewareGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-378v-28hj-76wf bn.js affected by an infinite loopGHSA-378v-28hj-76wf bn.js affected by an infinite loopGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-grv7-fg5c-xmjg Uncontrolled resource consumption in bracesGHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawnGHSA-434g-2637-qmqr Elliptic's verify function omits uniqueness validationGHSA-49q7-c7j4-3p7m Elliptic allows BER-encoded signaturesGHSA-848j-6mx2-7j84 Elliptic Uses a Cryptographic Primitive with a Risky ImplementationGHSA-977x-g7h5-7qgw Elliptic's ECDSA missing check for whether leading bit of r and s is zeroGHSA-f7q4-pwc6-w24p Elliptic's EDDSA missing signature length checkGHSA-fc9h-whq2-v747 Valid ECDSA signatures erroneously rejected in EllipticGHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phaseGHSA-rf6f-7fwh-wjgh Prototype Pollution via parse() in NodeJS flattedGHSA-52cp-r559-cp3m js-yaml: YAML merge-key chains can force quadratic CPU consumptionGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedGHSA-h67p-54hq-rp68 JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliasesGHSA-mh29-5h37-fv8m js-yaml has prototype pollution in merge (<<)Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.