Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2021-41116 Improper escaping of command arguments on Windows leading to command injectionCVE-2024-51736 CVE-2024-51736: Command execution hijack on Windows with Process classCVE-2022-21235 github.com/Masterminds/vcs: Command Injection via argument injectionCVE-2022-21235 github.com/Masterminds/vcs: Command Injection via argument injectionCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerabilityCVE-2022-37601 loader-utils: prototype pollution in function parseQuery in parseQuery.jsCVE-2021-44906 minimist: prototype pollutionCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2020-7677 thenify: Arbitrary Code Execution in thenifyCVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesCVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesCVE-2022-26184 Poetry before v1.1.9 contains Untrusted Search PathCVE-2021-29472 Composer is a dependency manager for PHP. URLs for Mercurial repositor ...CVE-2022-24828 Composer is a dependency manager for the PHP programming language. Int ...CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer. ...CVE-2026-40176 composer: command injection via malicious Perforce repository definitionCVE-2026-40261 composer: command injection via malicious Perforce source reference/urlCVE-2026-59948 composer/composer: Composer: Arbitrary file write via crafted package nameCVE-2026-45793 Composer is a dependency Manager for the PHP language. Prior to 1.10.2 ...CVE-2026-59946 composer: Composer: Insecure file permissions leading to information disclosure and potential executionCVE-2026-59947 composer/composer: Composer: Information disclosure of credentials via debug outputCVE-2026-24739 Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on WindowsCVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate functionCVE-2025-69873 ajv: ReDoS via $data referenceYour dependencies cross-checked against the OSV vulnerability database.
GO-2022-0414 Command injection in github.com/Masterminds/vcsGO-2022-0414 Command injection in github.com/Masterminds/vcsGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-29xr-v42j-r956 thenify before 3.3.1 made use of unsafe calls to `eval`.GHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashPYSEC-2022-234 Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing maliciGHSA-499r-g7pc-vmp9 Composer: Arbitrary file write outside vendor via malicious transitive package nameGHSA-f9f8-rm49-7jv2 Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logsGHSA-frqg-7g38-6gcf Improper escaping of command arguments on Windows leading to command injectionGHSA-g6xq-892h-64w3 Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)GHSA-gjfg-22fp-rrxx Composer: Path traversal in package bin field lets dependencies chmod arbitrary host filesGHSA-gqw4-4w2p-838q Composer has a command injection via malicious perforce referenceGHSA-h5h8-pc6h-jvvx Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with MercurialGHSA-jm6m-4632-36hf Composer Remote Code Execution vulnerability via web-accessible composer.pharGHSA-wg36-wvj6-r67p Composer has a command injection via malicious perforce repositoryGHSA-x7cr-6qr6-2hh6 Missing input validation can lead to command execution in composerGHSA-qq5c-677p-737q Symfony vulnerable to command execution hijack on Windows with Process classCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.