Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2026-9277 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminatorsCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2026-33068 Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings FileCVE-2026-39861 Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside WorkspaceCVE-2026-35603 Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowsCVE-2026-54316 claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetchCVE-2026-48068 grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiationCVE-2026-48069 grpc-js: @grpc/grpc-js: Client or server crash via malformed compressed messageCVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansionCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesCVE-2026-50146 Astro: Reflected XSS via unescaped slot nameCVE-2026-54299 Astro: Host header SSRF in prerendered error page fetchCVE-2026-41067 Astro: XSS in define:vars via incomplete </script> tag sanitizationCVE-2026-54298 Astro: XSS via Unescaped Attribute Names in Spread PropsCVE-2026-59729 Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)CVE-2026-73422 Astro: Reflected XSS via unescaped View Transition animation propertiesCVE-2026-25639 axios: Axios affected by Denial of Service via __proto__ Key in mergeConfigCVE-2026-42033 axios: Axios: HTTP Transport Hijacking via Prototype PollutionCVE-2026-42035 axios: Axios: Arbitrary HTTP header injection via prototype pollutionCVE-2026-42043 axios: Axios: NO_PROXY bypass via crafted URLCVE-2026-42264 axios: Axios: Prototype pollution allows information disclosure and request manipulationCVE-2026-44486 axios: Axios: Information disclosure of proxy credentials via HTTP redirectsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fg94-h982-f3mm Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetchGHSA-vp62-r36r-9xqp Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside WorkspaceGHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesGHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-3qcw-2rhx-2726 Turbo: Unexpected local code execution during Yarn Berry detectionGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-5cwg-9f6j-9jvx Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowsGHSA-mmgp-wc2j-qcv7 Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings FileGHSA-5375-pq7m-f5r2 @grpc/grpc-js: A malformed request can cause a server crashGHSA-99f4-grh7-6pcq @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crashGHSA-7h2j-956f-4vf2 @isaacs/brace-expansion has Uncontrolled Resource ConsumptionGHSA-q6x5-8v7m-xcrf protobufjs has overlong UTF-8 decodingGHSA-2pvr-wf23-7pc7 Astro: Host header SSRF in prerendered error page fetchGHSA-4g3v-8h47-v7g6 Astro: Reflected XSS via unescaped View Transition animation propertiesGHSA-8hv8-536x-4wqp Astro: Reflected XSS via unescaped slot nameGHSA-f48w-9m4c-m7f5 Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)GHSA-g735-7g2w-hh3f Astro: Remote allowlist bypass via unanchored matchPathname wildcardGHSA-j687-52p2-xcff Astro: XSS in define:vars via incomplete </script> tag sanitizationGHSA-jrpj-wcv7-9fh9 Astro: XSS via Unescaped Attribute Names in Spread PropsGHSA-xr5h-phrj-8vxv Astro: Server island encrypted parameters vulnerable to cross-component replayGHSA-35jp-ww65-95wh axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`GHSA-3g43-6gmg-66jw axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.