Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerabilityCVE-2025-25200 Inefficient Regular Expression Complexity in koaCVE-2021-44906 minimist: prototype pollutionCVE-2021-28918 nodejs-netmask: improper input validation of octal input dataCVE-2020-7769 This affects the package nodemailer before 6.4.16. Use of crafted reci ...CVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template functionCVE-2022-0686 npm-url-parse: Authorization bypass through user-controlled keyCVE-2018-1000620 nodejs-cryptiles: Insecure randomness causes the randomDigits() function returns a pseudo-random data string biased to certain digitsCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2018-3739 nodejs-https-proxy-agent: Unsanitized options passed to Buffer() allow for denial of serviceCVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerabilityCVE-2025-25200 Inefficient Regular Expression Complexity in koaCVE-2021-44906 minimist: prototype pollutionCVE-2021-28918 nodejs-netmask: improper input validation of octal input dataCVE-2020-7769 This affects the package nodemailer before 6.4.16. Use of crafted reci ...CVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template functionCVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate functionCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2021-43138 async: Prototype Pollution in asyncCVE-2019-10742 Axios up to and including 0.18.0 allows attackers to cause a denial of ...CVE-2021-3749 nodejs-axios: Regular expression denial of service in trim functionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-593f-38f6-jp5m Inefficient Regular Expression Complexity in koaGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-4c7m-wxvm-r7gc Improper parsing of octal bytes in netmaskGHSA-48ww-j4fc-435p Command injection in nodemailerGHSA-cf4h-3jhx-xvhq Arbitrary Code Execution in underscoreGHSA-hgjh-723h-mx2j Authorization Bypass Through User-Controlled Key in url-parseGHSA-rq8g-5pc5-wrhr Insufficient Entropy in cryptilesGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-86wf-436m-h424 Resource Exhaustion Denial of Service in http-proxy-agent GHSA-8g7p-74h8-hg48 Denial of Service in https-proxy-agentGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-593f-38f6-jp5m Inefficient Regular Expression Complexity in koaGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-4c7m-wxvm-r7gc Improper parsing of octal bytes in netmaskGHSA-48ww-j4fc-435p Command injection in nodemailerGHSA-cf4h-3jhx-xvhq Arbitrary Code Execution in underscoreGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-v88g-cgmw-v5xw Prototype Pollution in AjvGHSA-fwr7-v2mv-hh25 Prototype Pollution in asyncGHSA-3p68-rc4w-qgx5 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRFCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-shady-links shady-links match in telegraf 3.40.0A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.