Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisationCVE-2023-26119 HtmlUnit Code Injection vulnerabilityCVE-2015-3253 groovy: remote execution of untrusted code in class MethodClosureCVE-2016-6814 Groovy: Remote code execution via deserializationCVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisationCVE-2023-26119 HtmlUnit Code Injection vulnerabilityCVE-2015-3253 groovy: remote execution of untrusted code in class MethodClosureCVE-2016-6814 Groovy: Remote code execution via deserializationCVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by defaultCVE-2025-48734 commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by defaultCVE-2015-6420 Insecure Deserialization in Apache Commons CollectionCVE-2012-5783 jakarta-commons-httpclient: missing connection hostname check against X.509 certificate nameCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureCVE-2020-15250 junit4: TemporaryFolder is shared between all users across system which could result in information disclosureCVE-2023-26464 log4j1-socketappender: DoS via hashmap loggingCVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)CVE-2021-27568 json-smart: uncaught exception may lead to crash or information disclosureCVE-2020-5529 htmlunit: malicious JavaScript code leads to arbitrary java code executionCVE-2012-6153 CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fixCVE-2014-3577 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fixCVE-2015-5262 httpcomponents-core: missing HTTPS connection timeoutYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fjq5-5j5f-mvxh Deserialization of Untrusted Data in Apache commons collectionsGHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-3xrr-7m6p-p7xh HtmlUnit Code Injection vulnerabilityGHSA-qg25-hgjv-cg9q Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache GroovyGHSA-xphj-m9cc-8fmq Deserialization of Untrusted Data in GroovyGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-mvr2-9pj6-7w5j Denial of Service in Google GuavaGHSA-6phf-73q6-gh87 Insecure Deserialization in Apache Commons BeanutilsGHSA-wxr5-93ph-8wr9 Apache Commons Improper Access Control vulnerabilityGHSA-6hgm-866r-3cjv Insecure Deserialization in Apache Commons CollectionGHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderGHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IOGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-fp5r-v3w9-4333 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted dataGHSA-vp98-w2p3-mv35 Apache Log4j 1.x (EOL) allows Denial of Service (DoS)GHSA-w9p3-5cr8-m3jj Deserialization of Untrusted Data in Log4j 1.xGHSA-5mh9-r3rr-9597 Code execution vulnerability in HtmlUnitGHSA-2x83-r56g-cv47 Improper certificate validation in org.apache.httpcomponents:httpclientGHSA-7r82-7xv7-xcpj Cross-site scripting in Apache HttpClientGHSA-j8wc-gxx9-82hx Exposure of Sensitive Information to an Unauthorized Actor in Apache SantuarioGHSA-xfrj-6vvc-3xm2 Apache Santuario - XML Security for Java are vulnerable to private key disclosureCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.