Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-f82v-jwr5-mffw Authorization Bypass in Next.js MiddlewareGHSA-mwcw-c2x4-8c55 Predictable results in nanoid generation when given non-integer valuesGHSA-36qx-fr4f-26g5 Next.js has a Middleware / Proxy bypass in Pages Router applications using i18nGHSA-3x4c-7xq6-9pq8 Next.js: Unbounded next/image disk cache growth can exhaust storageGHSA-4342-x723-ch2f Next.js Improper Middleware Redirect Handling Leads to SSRFGHSA-7gfc-8cq8-jh5f Next.js authorization bypass vulnerabilityGHSA-9g9p-9gw9-jx7f Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configurationGHSA-g5qg-72qw-gw5v Next.js Affected by Cache Key Confusion for Image Optimization API RoutesGHSA-g77x-44xx-532m Denial of Service condition in Next.js image optimizationGHSA-ggv3-7p47-pfv8 Next.js: HTTP request smuggling in rewritesGHSA-h64f-5h5j-jqjh Next.js has a Denial of Service in the Image Optimization APIGHSA-xv57-4mr9-wg8v Next.js Content Injection Vulnerability for Image OptimizationGHSA-7fh5-64p2-3v2j PostCSS line return parsing errorGHSA-qx2v-qp2m-jg93 PostCSS has XSS via Unescaped </style> in its CSS Stringify OutputGHSA-m95q-7qp3-xv42 Zod denial of service vulnerabilityGHSA-3g8h-86w9-wvmq Next.js's Middleware / Proxy redirects can be cache-poisonedGHSA-c59h-r6p8-q9wc Next.js missing cache-control header may lead to CDN caching empty replyGHSA-qpjv-v59x-3qc4 Next.js Race Condition to Cache PoisoningCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 1.6/10scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Code-Review Code-Review scored 0: Found 0/5 approved changesets -- score normalized to 0scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-License License scored 0: license file not detectedscorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0scorecard-SAST SAST scored 0: no SAST tool detectedscorecard-Security-Policy Security-Policy scored 0: security policy file not detected