Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-18446 fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authorityCVE-2026-69207 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersCVE-2026-71848 Hono: Algorithmic Complexity DoS in Language MiddlewareCVE-2026-71850 Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureCVE-2026-69192 ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypassCVE-2026-54272 ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassificationCVE-2026-69198 ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypassCVE-2026-12590 body-parser: body-parser: Denial of Service via invalid limit optionCVE-2026-71849 Hono: Proxy Helper does not remove response headers listed in the `Connection` headerYour dependencies cross-checked against the OSV vulnerability database.
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-7p8r-x3mc-p8w7 fast-uri vulnerable to host confusion via backslash authority introducerGHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-54fx-42gc-7vw4 Hono: Algorithmic Complexity DoS in Language MiddlewareGHSA-8j4g-w8fx-2239 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersGHSA-f23p-vx2j-j53r Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureGHSA-22jq-vg5j-6vgg ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checksGHSA-4xrf-jv44-h6hh ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checksGHSA-mwp4-54f8-5fhr ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypassGHSA-v422-hmwv-36x6 body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementGHSA-79qm-7rj5-m7r9 Hono: Proxy Helper does not remove response headers listed in the `Connection` headerCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.