Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2025-30223 Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User InputCVE-2024-25124 Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with CredentialsCVE-2024-38513 Session Middleware Token Injection VulnerabilityCVE-2025-66630 github.com/gofiber/fiber/v2: Fiber: Predictable UUIDs from randomness source errors can lead to security bypassesCVE-2025-12543 undertow-core: Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRFCVE-2024-40464 Beego privilege escalation vulnerabilityCVE-2024-40465 Beego privilege escalation vulnerabilityCVE-2024-55885 Beego has Collision Hazards of MD5 in Cache Key FilenamesGHSA-vrw8-fxc6-2r93 chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashesCVE-2025-54801 Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in DecoderCVE-2026-25882 Fiber has a Denial of Service Vulnerability via Route Parameter OverflowCVE-2026-42554 Fiber vulnerable to XSS in AutoFormat Content NegotiationCVE-2026-45045 GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForwardCVE-2023-6481 logback: A serialization vulnerability in logback receiverCVE-2024-12798 logback-core: arbitrary code execution via JaninoEventEvaluatorCVE-2025-11226 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-coreCVE-2026-42583 netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoderCVE-2026-59901 io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)CVE-2025-58057 netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attackCVE-2026-33870 io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension valuesCVE-2026-42584 netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusionCVE-2026-42587 netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompressionCVE-2026-55831 io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processingCVE-2026-55833 netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplificationCVE-2026-56745 netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codecYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.