Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-22051 commonmarker: integer overflow in cmark-gfm's table row parsing may lead to heap memory corruptionCVE-2026-54906 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of serviceCVE-2021-28834 rubygem-kramdown: allows arbitrary classes to be instantiatedGHSA-353f-x4gh-cqq8 Nokogiri patches vendored libxml2 to resolve multiple CVEsCVE-2023-22796 rubygem-activesupport: Regular Expression Denial of ServiceCVE-2026-33176 Rails: Active Support: Active Support: Denial of Service via large scientific notation stringsCVE-2023-28120 rubygem-activesupport: Possible XSS in SafeBuffer#bytespliceCVE-2023-38037 rubygem-activesupport: File Disclosure of Locally Encrypted FilesCVE-2026-33169 rails: rails-activesupport: Active Support: Denial of Service via crafted long digit stringsCVE-2026-33170 Rails: Active Support: Active Support: Cross-Site Scripting (XSS) due to improper HTML safety flag propagation in SafeBuffer#%CVE-2021-32740 rubygem-addressable: ReDoS in templatesCVE-2026-35611 addressable: Addressable: Denial of Service via crafted URI templatesCVE-2023-37463 cmark-gfm is an extended version of the C reference implementation of ...GHSA-48wp-p9qv-4j64 Commonmarker vulnerable to to several quadratic complexity bugs that may lead to denial of serviceGHSA-4qw4-jpp4-8gvp Unbounded resource exhaustion in cmark-gfm autolink extension may lead to denial of serviceGHSA-636f-xm5j-pj9m Several quadratic complexity bugs may lead to denial of service in CommonmarkerGHSA-7vh7-fw88-wj87 Several quadratic complexity bugs may lead to denial of service in CommonmarkerCVE-2026-54904 concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#updateCVE-2026-54905 concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusionCVE-2026-54297 faraday: Faraday: Denial of Service via crafted nested query stringsCVE-2026-25765 Faraday: Faraday: Server-Side Request Forgery via protocol-relative URLsCVE-2018-25032 zlib: A flaw found in zlib when compressing (not decompressing) certain inputsCVE-2021-30560 Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 a ...CVE-2021-3517 libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.cCVE-2021-3518 libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.cYour dependencies cross-checked against the OSV vulnerability database.
Nothing found by this check. ✓
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.