Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2022-2421 Insufficient validation when decoding a Socket.IO packetCVE-2022-2421 Insufficient validation when decoding a Socket.IO packetCVE-2020-28502 nodejs-xmlhttprequest: Code injection through user input to xhr.sendCVE-2021-31597 xmlhttprequest-ssl: SSL certificate validation disabled by defaultCVE-2022-2421 Insufficient validation when decoding a Socket.IO packetCVE-2022-2421 Insufficient validation when decoding a Socket.IO packetCVE-2020-28502 nodejs-xmlhttprequest: Code injection through user input to xhr.sendCVE-2021-31597 xmlhttprequest-ssl: SSL certificate validation disabled by defaultCVE-2023-45133 babel: arbitrary code executionCVE-2023-28131 Expo SDK has an OAuth vulnerabilityCVE-2020-1911 Access of Resource Using Incompatible Type in Facebook HermesCVE-2020-1914 Always-Incorrect Control Flow Implementation in Facebook HermesCVE-2021-24037 Use After Free in HermesCVE-2021-24044 Access of Resource Using Incompatible Type in HermesCVE-2020-8149 Arbitrary shell command execution in logkittyCVE-2021-44906 minimist: prototype pollutionCVE-2022-22912 Prototype pollution in Plist before 3.0.5 can cause denial of serviceCVE-2026-9277 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminatorsCVE-2022-26260 Prototype Pollution in simple-plistCVE-2022-2421 Insufficient validation when decoding a Socket.IO packetCVE-2022-2421 Insufficient validation when decoding a Socket.IO packetCVE-2022-0686 npm-url-parse: Authorization bypass through user-controlled keyCVE-2020-28502 nodejs-xmlhttprequest: Code injection through user input to xhr.sendCVE-2021-31597 xmlhttprequest-ssl: SSL certificate validation disabled by defaultCVE-2025-7783 form-data: Unsafe random function in form-dataYour dependencies cross-checked against the OSV vulnerability database.
GHSA-qm95-pgcg-qqfq Insufficient validation when decoding a Socket.IO packetGHSA-qm95-pgcg-qqfq Insufficient validation when decoding a Socket.IO packetGHSA-72mh-269x-7mh5 Improper Certificate Validation in xmlhttprequest-sslGHSA-h4j5-c7cj-74xg xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code InjectionGHSA-qm95-pgcg-qqfq Insufficient validation when decoding a Socket.IO packetGHSA-qm95-pgcg-qqfq Insufficient validation when decoding a Socket.IO packetGHSA-72mh-269x-7mh5 Improper Certificate Validation in xmlhttprequest-sslGHSA-h4j5-c7cj-74xg xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code InjectionGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-wr5g-q49g-548w Expo SDK has an OAuth vulnerabilityGHSA-327c-qx3v-h673 Always-Incorrect Control Flow Implementation in Facebook HermesGHSA-7mhc-prgv-r3q4 Access of Resource Using Incompatible Type in HermesGHSA-f5x2-xv93-4p23 Access of Resource Using Incompatible Type in Facebook HermesGHSA-mph8-6787-r8hw Use After Free in HermesGHSA-v8v8-6859-qxm4 Arbitrary shell command execution in logkittyGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-4cpg-3vgw-4877 Prototype pollution in Plist before 3.0.5 can cause denial of serviceGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-gff7-g5r8-mg8m Prototype Pollution in simple-plistGHSA-qm95-pgcg-qqfq Insufficient validation when decoding a Socket.IO packetGHSA-qm95-pgcg-qqfq Insufficient validation when decoding a Socket.IO packetGHSA-hgjh-723h-mx2j Authorization Bypass Through User-Controlled Key in url-parseGHSA-crh6-fp67-6883 xmldom allows multiple root nodes in a DOMGHSA-72mh-269x-7mh5 Improper Certificate Validation in xmlhttprequest-sslGHSA-h4j5-c7cj-74xg xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code InjectionCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.