Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parserCVE-2024-29041 express: cause malformed URLs to be evaluatedCVE-2022-23539 jsonwebtoken: Unrestricted key type could lead to legacy keys usagenCVE-2022-23540 jsonwebtoken: Insecure default algorithm in jwt.verify() could lead to signature validation bypassCVE-2022-23541 jsonwebtoken: Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMACCVE-2025-65945 node-jws: auth0/node-jws: Improper signature verification in HS256 algorithmCVE-2024-45296 path-to-regexp: Backtracking regular expressions cause ReDoSCVE-2024-52798 path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.xCVE-2026-4867 path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parametersCVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsingCVE-2022-25883 nodejs-semver: Regular expression denial of serviceCVE-2026-41907 uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentialityCVE-2026-12590 body-parser: body-parser: Denial of Service via invalid limit optionCVE-2024-47764 cookie: cookie accepts cookie name, path, and domain with out of bounds charactersCVE-2024-47764 cookie: cookie accepts cookie name, path, and domain with out of bounds charactersCVE-2024-43796 express: Improper Input Handling in Express RedirectsCVE-2026-2391 qs: qs's arrayLimit bypass in comma parsing allows denial of serviceCVE-2024-43799 send: Code Execution Vulnerability in Send LibraryCVE-2024-43800 serve-static: Improper Sanitization in serve-staticYour dependencies cross-checked against the OSV vulnerability database.
GHSA-qwcr-r2fm-qrc7 body-parser vulnerable to denial of service when url encoding is enabledGHSA-qw6h-vgh9-j6wx express vulnerable to XSS via response.redirect()GHSA-rv95-896h-c2vc Express.js Open Redirect in malformed URLsGHSA-8cf7-32gw-wr33 jsonwebtoken unrestricted key type could lead to legacy keys usage GHSA-hjrf-2m68-5959 jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMACGHSA-qwph-4952-7xr6 jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()GHSA-869p-cjfg-cm3x auth0/node-jws Improperly Verifies HMAC SignatureGHSA-37ch-88jc-xwx2 path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parametersGHSA-rhx6-c78j-4q9w path-to-regexp contains a ReDoSGHSA-6rw7-vpxm-498p qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustionGHSA-c2qf-rxjj-qqgw semver vulnerable to Regular Expression Denial of ServiceGHSA-m6fv-jmcg-4jfg send vulnerable to template injection that can lead to XSSGHSA-cm22-4g7w-348p serve-static vulnerable to template injection that can lead to XSSGHSA-w5hq-g745-h8pq uuid: Missing buffer bounds check in v3/v5/v6 when buf is providedGHSA-v422-hmwv-36x6 body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementGHSA-pxg6-pf52-xh8x cookie accepts cookie name, path, and domain with out of bounds charactersGHSA-pxg6-pf52-xh8x cookie accepts cookie name, path, and domain with out of bounds charactersGHSA-w7fw-mjwx-w883 qs's arrayLimit bypass in comma parsing allows denial of serviceGO-2023-2041 Improper handling of HTML-like comments in script contexts in html/templateGO-2023-2043 Improper handling of special tags within script contexts in html/templateGO-2023-2102 HTTP/2 rapid reset can cause excessive work in net/httpGO-2023-2185 Insecure parsing of Windows paths with a \??\ prefix in path/filepathGO-2023-2186 Incorrect detection of reserved device names on Windows in path/filepathGO-2023-2375 Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channelGO-2023-2382 Denial of service via chunk extensions in net/httpCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.