Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2025-29927 nextjs: Authorization Bypass in Next.js MiddlewareCVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2025-9288 sha.js: Missing type checks leading to hash rewind and passing on crafted dataCVE-2026-9277 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminatorsCVE-2026-54466 websocket-driver: Message corruption via abuse of protocol length headersCVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2026-44728 Babel is a compiler for writing next generation JavaScript. From 7.12. ...CVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2025-27789 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsCVE-2026-48068 grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiationCVE-2026-48069 grpc-js: @grpc/grpc-js: Client or server crash via malformed compressed messageCVE-2024-37168 grps-js: allocate memory for incoming messages well above configured limitsCVE-2025-56648 parcel: Parcel Origin Validation ErrorCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesCVE-2026-22029 @remix-run/router: react-router: React Router vulnerable to XSS via Open RedirectsGHSA-593m-55hh-j8gv Sentry SDK Prototype Pollution gadget in JavaScript SDKsCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2025-27611 base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation.CVE-2026-33750 brace-expansion: brace-expansion: Denial of Service via zero step value in brace patternCVE-2026-33750 brace-expansion: brace-expansion: Denial of Service via zero step value in brace patternCVE-2024-4068 braces: fails to limit the number of characters it can handleCVE-2024-21538 cross-spawn: regular expression denial of serviceGHSA-67mh-4wv8-2f99 esbuild enables any website to send any requests to the development server and read the responseYour dependencies cross-checked against the OSV vulnerability database.
GHSA-cpq7-6gpm-g9rc cipher-base is missing type checks, leading to hash rewind and passing on crafted dataGHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)GHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-wf6x-7x77-mvgw Immutable is vulnerable to Prototype PollutionGHSA-f82v-jwr5-mffw Authorization Bypass in Next.js MiddlewareGHSA-9qr9-h5gf-34mp Next.js is vulnerable to RCE in React flight protocolGHSA-f82v-jwr5-mffw Authorization Bypass in Next.js MiddlewareGHSA-h7cp-r72f-jxh6 pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algosGHSA-v62p-rq8g-8h59 pbkdf2 silently disregards Uint8Array input, returning static keysGHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-95m3-7q98-8xr5 sha.js is missing type checks leading to hash rewind and passing on crafted dataGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-3qcw-2rhx-2726 Turbo: Unexpected local code execution during Yarn Berry detectionGHSA-xv26-6w52-cph6 websocket-driver: Message corruption via abuse of protocol length headersGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-fv7c-fp4j-7gwp @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious inputGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-5375-pq7m-f5r2 @grpc/grpc-js: A malformed request can cause a server crashGHSA-7v5v-9h63-cj86 @grpc/grpc-js can allocate memory for incoming messages well above configured limitsGHSA-99f4-grh7-6pcq @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crashGHSA-qm9p-f9j5-w83w Parcel has an Origin Validation Error vulnerabilityGHSA-q6x5-8v7m-xcrf protobufjs has overlong UTF-8 decodingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 5.1/10scorecard-CI-Tests CI-Tests scored 0: 0 out of 27 merged PRs checked by a CI test -- score normalized to 0scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0scorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0scorecard-SAST SAST scored 0: SAST tool is not run on all commits -- score normalized to 0scorecard-Token-Permissions Token-Permissions scored 0: detected GitHub workflow tokens with excessive permissions