Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-35611 addressable: Addressable: Denial of Service via crafted URI templatesCVE-2025-14762 aws-sdk-ruby: AWS SDK for Ruby: Data integrity compromise via missing cryptographic key commitmentCVE-2026-54171 Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...CVE-2026-54297 faraday: Faraday: Denial of Service via crafted nested query stringsCVE-2026-25765 Faraday: Faraday: Server-Side Request Forgery via protocol-relative URLsCVE-2026-45363 ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verificationCVE-2024-49761 rexml: REXML ReDoS vulnerabilityCVE-2024-35176 REXML: DoS parsing an XML with many `<`s in an attribute valueCVE-2024-39908 rexml: DoS vulnerability in REXMLCVE-2024-41123 rexml: rubygem-rexml: DoS when parsing an XML having many specific characters such as whitespace character, >] and ]>CVE-2024-41946 rexml: DoS vulnerability in REXMLCVE-2024-43398 rexml: DoS vulnerability in REXMLYour dependencies cross-checked against the OSV vulnerability database.
GHSA-h27x-rffw-24p4 Addressable has a Regular Expression Denial of Service in Addressable templatesGHSA-2xgq-q749-89fq AWS SDK for Ruby's S3 Encryption Client has a Key Commitment IssueGHSA-48rx-c7pg-q66r Excon does not redact additional sensitive/risky headers when following redirectsGHSA-33mh-2634-fwr2 Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_urlGHSA-98m9-hrrm-r99r Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parametersGHSA-c32j-vqhx-rx3x ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351GHSA-2rxp-v6pw-ch6m REXML ReDoS vulnerabilityGHSA-4xqq-m2hx-25v8 REXML denial of service vulnerabilityGHSA-5866-49gr-22v4 REXML DoS vulnerabilityGHSA-r55c-59qm-vjw6 REXML DoS vulnerabilityGHSA-vg3r-rm7w-2xgh REXML contains a denial of service vulnerabilityGHSA-vmwr-mc7x-5vc3 REXML denial of service vulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.