Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-4068 braces: fails to limit the number of characters it can handleCVE-2023-26920 fast-xml-parser vulnerable to Prototype Pollution through tag or attribute nameCVE-2026-41650 fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequencesCVE-2020-28469 nodejs-glob-parent: Regular expression denial of serviceCVE-2026-33671 picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patternsCVE-2026-33672 picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressionsCVE-2024-37890 nodejs-ws: denial of service when handling a request with many HTTP headersCVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsCVE-2021-32640 nodejs-ws: Specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws serverYour dependencies cross-checked against the OSV vulnerability database.
GHSA-grv7-fg5c-xmjg Uncontrolled resource consumption in bracesGHSA-gh4j-gqv2-49f6 fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped DelimitersGHSA-x3cc-x39p-42qx fast-xml-parser vulnerable to Prototype Pollution through tag or attribute nameGHSA-ww39-953v-wcq6 glob-parent vulnerable to Regular Expression Denial of Service in enclosure regexGHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob MatchingGHSA-c2c7-rcm5-vvqj Picomatch has a ReDoS vulnerability via extglob quantifiersGHSA-3h5v-q93c-6h6q ws affected by a DoS when handling a request with many HTTP headersGHSA-6fc8-4gx4-v693 ReDoS in Sec-Websocket-Protocol headerGHSA-96hv-2xvq-fx4p ws: Memory exhaustion DoS from tiny fragments and data chunksCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.