Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesCVE-2022-29248 Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 ...CVE-2022-31042 Guzzle is an open source PHP HTTP client. In affected versions the `Co ...CVE-2022-31043 Guzzle is an open source PHP HTTP client. In affected versions `Author ...CVE-2022-31090 Guzzle, an extensible PHP HTTP client. `Authorization` headers on requ ...CVE-2022-31091 Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` he ...CVE-2026-69246 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...CVE-2026-55568 Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain c ...CVE-2026-55767 Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar in ...CVE-2026-59883 guzzle/guzzle: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar.CVE-2026-67339 guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...CVE-2026-67353 guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...CVE-2026-67354 guzzlehttp/guzzle versions before 7.15.1 contain an information disclo ...CVE-2026-67355 guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...CVE-2026-69245 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...CVE-2022-24775 guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8 ...CVE-2023-29197 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2026-48998 guzzlehttp/psr7: guzzlehttp/psr7: Information disclosure via improper Host header validationCVE-2026-49214 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2026-55766 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2026-59882 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...CVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documentsGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-cpq7-6gpm-g9rc cipher-base is missing type checks, leading to hash rewind and passing on crafted dataGHSA-phwq-j96m-2c2q ejs template injection vulnerabilityGHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)GHSA-3gx7-xhv7-5mx3 Arbitrary Code Execution in eslint-utilsGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-vvj3-85vf-fgmw global-modules-path Command Injection vulnerabilityGHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type ConfusionGHSA-765h-qjxv-5f44 Prototype Pollution in handlebarsGHSA-f2jv-r9rf-7988 Remote code execution in handlebars when compiling templatesGHSA-w457-6q6x-cgp9 Prototype Pollution in handlebarsGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-r6rj-9ch6-g264 Prototype pollution in Merge-deepGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-h7cp-r72f-jxh6 pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algosGHSA-v62p-rq8g-8h59 pbkdf2 silently disregards Uint8Array input, returning static keysGHSA-95m3-7q98-8xr5 sha.js is missing type checks leading to hash rewind and passing on crafted dataGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.