Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisationCVE-2023-2976 guava: insecure temporary directory creationCVE-2015-6420 Insecure Deserialization in Apache Commons CollectionCVE-2012-5783 jakarta-commons-httpclient: missing connection hostname check against X.509 certificate nameCVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6CVE-2012-6153 CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fixCVE-2011-1498 Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used ...CVE-2014-3577 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fixCVE-2015-5262 httpcomponents-core: missing HTTPS connection timeoutCVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIsCVE-2012-0881 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)CVE-2013-4002 OpenJDK: XML parsing Denial of Service (JAXP, 8017298)CVE-2009-2625 JDK: XML parsing Denial-Of-Service (6845701)CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImplCVE-2022-23437 xerces-j2: infinite loop when handling specially crafted XML document payloadsCVE-2012-5783 jakarta-commons-httpclient: missing connection hostname check against X.509 certificate nameCVE-2012-6153 CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fixCVE-2011-1498 Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used ...CVE-2014-3577 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fixCVE-2015-5262 httpcomponents-core: missing HTTPS connection timeoutCVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIsCVE-2012-6153 CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fixCVE-2011-1498 Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used ...CVE-2014-3577 CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fixCVE-2015-5262 httpcomponents-core: missing HTTPS connection timeoutYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fjq5-5j5f-mvxh Deserialization of Untrusted Data in Apache commons collectionsGHSA-hwj3-m3p6-hj38 dom4j allows External Entities by default which might enable XXE attacksGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-7p3p-8qv8-m2vh Eclipse Jetty: HTTP Authority/Host mismatchGHSA-9299-c6m4-mjhc Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsGHSA-g8m5-722r-8whq Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksGHSA-qw69-rqj8-6qw8 OutOfMemoryError for large multipart without filename in Eclipse JettyGHSA-j26w-f9rq-mr2q Eclipse Jetty has a denial of service vulnerability on DosFilterGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-6hgm-866r-3cjv Insecure Deserialization in Apache Commons CollectionGHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IOGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-6pcc-3rfx-4gpm Dom4j contains a XML Injection vulnerabilityGHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-hmr7-m48g-48f6 Jetty accepts "+" prefixed value in Content-LengthGHSA-qh8g-58pp-2wxh Eclipse Jetty URI parsing of invalid authorityGHSA-2fvj-hgj9-j2gr Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionGHSA-hh26-6xwr-ggv7 Denial of service in Spring FrameworkGHSA-4gc7-5j7h-4qph Spring Framework DataBinder Case Sensitive Match ExceptionGHSA-g5mm-vmx4-3rg7 Improper handling of case sensitivity in Spring FrameworkGHSA-4487-x383-qpph Possible privilege escalation in org.springframework:spring-coreGHSA-8crv-49fr-2h6j Spring Security and Spring Framework may not recognize certain paths that should be protectedGHSA-g8hw-794c-4j9g Path Traversal in org.springframework:spring-coreGHSA-pgf9-h69p-pcgf Files or Directories Accessible to External Parties in org.springframework:spring-coreGHSA-rcpf-vj53-7h2m Denial of Service in org.springframework:spring-coreCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.