Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled KeyCVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validationCVE-2017-5929 logback: Serialization vulnerability in SocketServer and ServerSocketReceiverCVE-2017-15095 jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525)CVE-2017-17485 jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095)CVE-2017-7525 jackson-databind: Deserialization vulnerability via readValue method of ObjectMapperCVE-2018-11307 jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatisCVE-2018-14718 jackson-databind: arbitrary code execution in slf4j-ext classCVE-2018-14719 jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classesCVE-2018-14720 jackson-databind: exfiltration/XXE in some JDK classesCVE-2018-14721 jackson-databind: server-side request forgery (SSRF) in axis2-jaxws classCVE-2018-19360 jackson-databind: improper polymorphic deserialization in axis2-transport-jms classCVE-2018-19361 jackson-databind: improper polymorphic deserialization in openjpa classCVE-2018-19362 jackson-databind: improper polymorphic deserialization in jboss-common-core classCVE-2018-7489 jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 librariesCVE-2019-14379 jackson-databind: default typing mishandling leading to remote code executionCVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfigCVE-2019-16335 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSourceCVE-2019-16942 jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.*CVE-2019-16943 jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSourceCVE-2019-17267 jackson-databind: Serialization gadgets in classes of the ehcache packageCVE-2019-17531 jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*Your dependencies cross-checked against the OSV vulnerability database.
GO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/cryptoGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshGO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGO-2026-4762 Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpcGO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/cryptoGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshGO-2022-0619 Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3GO-2024-3321 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/cryptoGO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.