Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2026-31808 file-type: file-type: Denial of Service due to infinite loop in ASF file parsingCVE-2026-12143 form-data: form-data: Form field override via CRLF injectionCVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template importsCVE-2025-13465 lodash: prototype pollution in _.unset and _.omit functionsCVE-2026-2950 lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypassCVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsingCVE-2023-26136 tough-cookie: prototype pollution in cookie memstoreCVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket framesCVE-2026-1526 undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompressionCVE-2026-2229 undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameterCVE-2025-22150 undici: Undici Uses Insufficiently Random ValuesCVE-2026-15157 undici: undici: HTTP header injection via unvalidated blob-like body type propertyCVE-2026-1525 undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headersCVE-2026-1527 undici: Undici: HTTP header injection and request smuggling vulnerabilityCVE-2026-16728 undici: undici: Response desynchronization via retry interceptor with mismatched Content-LengthCVE-2026-16729 undici: Undici: Cookie attribute injection allows bypassing security protectionsCVE-2026-22036 undici: Undici: Denial of Service via excessive decompression stepsCVE-2026-9679 undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingCVE-2026-41907 uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentialityCVE-2024-37890 nodejs-ws: denial of service when handling a request with many HTTP headersCVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsCVE-2026-45736 ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`CVE-2023-45143 node-undici: cookie leakageYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-5v7r-6r5c-r473 file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-headerGHSA-hmw2-7cc7-3qxx form-data: CRLF injection in form-data via unescaped multipart field names and filenamesGHSA-f23m-r3pf-42rh lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`GHSA-r5fr-rjxr-66jc lodash vulnerable to Code Injection via `_.template` imports key namesGHSA-6rw7-vpxm-498p qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustionGHSA-p8p7-x288-28g6 Server-Side Request Forgery in RequestGHSA-72xf-g2v4-qvf3 tough-cookie Prototype Pollution vulnerabilityGHSA-2mjp-6q6p-2qxm Undici has an HTTP Request/Response Smuggling issueGHSA-4992-7rv2-5pvq Undici has CRLF Injection in undici via `upgrade` optionGHSA-8xcm-r25x-g524 undici vulnerable to downstream response desynchronization via retry interceptorGHSA-c76h-2ccp-4975 Use of Insufficiently Random Values in undiciGHSA-g9mf-h72j-4rw9 Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionGHSA-m8rv-5g2x-5cg5 undici vulnerable to CRLF Injection via blob-like body 'type' propertyGHSA-p88m-4jfj-68fv undici vulnerable to HTTP header injection via Set-Cookie percent-decodingGHSA-v3r7-h72x-cjcm undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fieldsGHSA-v9p9-hfj2-hcw8 Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits ValidationGHSA-vrm6-8vpv-qv8q Undici has Unbounded Memory Consumption in WebSocket permessage-deflate DecompressionGHSA-vxpw-j846-p89q undici WebSocket client vulnerable to denial of service via fragment count bypassGHSA-w5hq-g745-h8pq uuid: Missing buffer bounds check in v3/v5/v6 when buf is providedGHSA-3h5v-q93c-6h6q ws affected by a DoS when handling a request with many HTTP headersGHSA-58qx-3vcg-4xpx ws: Uninitialized memory disclosureGHSA-96hv-2xvq-fx4p ws: Memory exhaustion DoS from tiny fragments and data chunksGHSA-35p6-xmwp-9g52 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuseCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.