Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2023-6378 logback: serialization vulnerability in logback receiverCVE-2024-12798 logback-core: arbitrary code execution via JaninoEventEvaluatorCVE-2025-11226 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-coreCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2025-49128 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocationCVE-2020-25649 jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)CVE-2020-36518 jackson-databind: denial of service via a large depth of nested objectsCVE-2021-46877 jackson-databind: Possible DoS if using JDK serialization to serialize JsonNodeCVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYSCVE-2022-42004 jackson-databind: use of deeply nested arraysCVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypassCVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code executionCVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processingCVE-2026-54514 jackson-databind: jackson-databind: Information Disclosure via Eager DNS ResolutionCVE-2026-54515 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modifiedCVE-2021-0341 okhttp: information disclosure via improperly used cryptographic functionCVE-2023-3635 okio: GzipSource class improper exception handlingCVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2024-25710 commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP fileCVE-2024-26308 commons-compress: OutOfMemoryError unpacking broken Pack200 fileCVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2025-67030 org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile methodCVE-2021-37714 jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuckYour dependencies cross-checked against the OSV vulnerability database.
Nothing found by this check. ✓
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.