Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2020-7981 sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection whe ...CVE-2016-4658 libxml2: Use after free via namespace node in XPointer rangesCVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URLCVE-2019-5477 A command injection vulnerability in Nokogiri v1.10.3 and earlier allo ...GHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsCVE-2022-30123 rubygem-rack: crafted requests can cause shell escape sequencesCVE-2026-54297 faraday: Faraday: Denial of Service via crafted nested query stringsCVE-2026-25765 Faraday: Faraday: Server-Side Request Forgery via protocol-relative URLsCVE-2020-10663 rubygem-json: Unsafe object creation vulnerability in JSONCVE-2026-45363 ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verificationCVE-2017-15412 libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.cCVE-2017-16932 libxml2: Infinite recursion in parameter entitiesCVE-2017-5029 chromium-browser: integer overflow in libxsltCVE-2017-9050 libxml2: Heap-based buffer over-read in function xmlDictAddStringCVE-2018-14404 libxml2: NULL pointer dereference in xmlXPathCompOpEval() function in xpath.cCVE-2018-25032 zlib: A flaw found in zlib when compressing (not decompressing) certain inputsCVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid characterCVE-2019-18197 libxslt: use after free in xsltCopyText in transform.c could lead to information disclosureCVE-2019-5815 chromium-browser: Heap buffer overflow in BlinkCVE-2020-7595 libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situationsCVE-2021-30560 Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 a ...CVE-2021-3517 libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.cCVE-2021-3518 libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.cCVE-2021-41098 rubygem-nokogiri: XEE on JRubyCVE-2022-24836 nokogiri: ReDoS in HTML encoding detectionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-864j-6qpp-cmrr SQL Injection in GeocoderGHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsGHSA-cr5j-953j-xw5p Nokogiri Command Injection VulnerabilityGHSA-fr52-4hqw-p27f Nokogiri does not forbid namespace nodes in XPointer rangesGHSA-qxcg-xjjg-66mj Nokogiri vulnerable to libxslt protection mechanism bypassGHSA-wq4h-7r42-5hrr Possible shell escape sequence injection vulnerability in RackGHSA-jphg-qwrw-7w9g Unsafe object creation in json RubyGemGHSA-c32j-vqhx-rx3x ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351GHSA-242x-7cm6-4w8j Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerabilityGHSA-286v-pcf5-25rc Nokogiri Implements libxml2 version vulnerable to null pointer dereferencingGHSA-2rr5-8q37-2w7h Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRubyGHSA-4hm9-844j-jmxp Uninitialized read in Nokogiri gemGHSA-59gp-qqm7-cw4j Nokogiri has vulnerable dependencies on libxml2 and libxsltGHSA-5prr-v3j2-97mh Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-62qp-3fxm-9wxf Nokogiri vulnerable to DoS while parsing XML documentsGHSA-6qvp-r6r3-9p7h Nokogiri NULL Pointer DereferenceGHSA-7553-jr98-vx47 libxml as used in Nokogiri has an infinite loop in a certain end-of-file situationGHSA-882p-jqgm-f45g Uncontrolled resource consumption in nokogiriGHSA-8c56-cpmw-89x7 Out-of-bounds read in nokogiriGHSA-c4rq-3m3g-8wgx Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-cf46-6xxh-pc75 libxslt Type Confusion vulnerability that affects NokogiriGHSA-cgx6-hpwq-fhv5 Integer Overflow or Wraparound in libxml2 affects NokogiriGHSA-crjr-9rc5-ghw8 Nokogiri Inefficient Regular Expression ComplexityGHSA-fq42-c5rg-92c2 Vulnerable dependencies in NokogiriGHSA-gx8x-g87m-h5q6 Denial of Service (DoS) in Nokogiri on JRubyCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.