Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-42033 axios: Axios: HTTP Transport Hijacking via Prototype PollutionCVE-2026-42035 axios: Axios: Arbitrary HTTP header injection via prototype pollutionCVE-2026-42043 axios: Axios: NO_PROXY bypass via crafted URLCVE-2026-42264 Axios is a promise based HTTP client for the browser and Node.js. From ...CVE-2026-44492 axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)CVE-2026-44494 axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`CVE-2026-44495 axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeCVE-2026-42034 axios: Axios: Denial of Service via oversized streamed uploads bypassing body limitsCVE-2026-42036 axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is usedCVE-2026-42037 axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type headerCVE-2026-42038 axios: Axios: Information disclosure due to `no_proxy` bypassCVE-2026-42039 axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request dataCVE-2026-42041 axios: Axios: Authentication bypass due to prototype pollution of HTTP error handlingCVE-2026-42042 axios: Axios: XSRF token bypass leading to information disclosureCVE-2026-42044 axios: Axios: Invisible JSON Response Tampering via Prototype Pollution GadgetCVE-2026-44490 axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functionsCVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policiesCVE-2026-6322 fast-uri normalize() decoded percent-encoded authority delimiters insi ...GHSA-r4q5-vmmm-2653 follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect TargetsCVE-2026-44455 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionCVE-2026-44456 Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsCVE-2026-44457 Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageCVE-2026-44458 Hono has CSS Declaration Injection via Style Object Values in JSX SSRGHSA-458j-xx4x-4375 hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSRCVE-2026-42338 ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-35jp-ww65-95wh axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`GHSA-3g43-6gmg-66jw axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeGHSA-3w6x-2g7m-8v23 Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`GHSA-445q-vr5w-6q77 Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamGHSA-5c9x-8gcm-mpgx Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0GHSA-62hf-57xw-28j9 Axios: unbounded recursion in toFormData causes DoS via deeply nested request dataGHSA-6chq-wfr3-2hj9 Axios: Header Injection via Prototype PollutionGHSA-898c-q2cr-xwhg axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functionsGHSA-m7pr-hjqh-92cm Axios: no_proxy bypass via IP alias allows SSRFGHSA-pf86-5x62-jrwf Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request HijackingGHSA-pjwm-pj3p-43mv axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)GHSA-pmwg-cvhr-8vh7 Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0GHSA-q8qp-cvcw-x6jj Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijackingGHSA-vf2m-468p-8v99 Axios: HTTP adapter streamed responses bypass maxContentLengthGHSA-w9j2-pvgh-6h63 Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge StrategyGHSA-xx6v-rp6x-q39c Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean CoercionGHSA-q3j6-qgpj-74h6 fast-uri vulnerable to path traversal via percent-encoded dot segmentsGHSA-v39h-62p7-jpjc fast-uri vulnerable to host confusion via percent-encoded authority delimitersGHSA-r4q5-vmmm-2653 follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect TargetsGHSA-458j-xx4x-4375 hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSRGHSA-69xw-7hcm-h432 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionGHSA-9vqf-7f2p-gf9v Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsGHSA-p77w-8qqv-26rm Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageGHSA-qp7p-654g-cw7p Hono has CSS Declaration Injection via Style Object Values in JSX SSRGHSA-v2v4-37r5-5v8g ip-address has XSS in Address6 HTML-emitting methodsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 2.9/10scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Code-Review Code-Review scored 0: Found 0/5 approved changesets -- score normalized to 0scorecard-Contributors Contributors scored 0: project has 0 contributing companies or organizations -- score normalized to 0scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Maintained Maintained scored 0: project was created within the last 90 days. Please review its contents carefullyscorecard-SAST SAST scored 0: no SAST tool detectedscorecard-Security-Policy Security-Policy scored 0: security policy file not detectedscorecard-Token-Permissions Token-Permissions scored 0: detected GitHub workflow tokens with excessive permissions