Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
gcp-api-key Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches.Packages you depend on that have known security holes (CVEs).
CVE-2021-44906 minimist: prototype pollutionCVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template functionCVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parserCVE-2024-21538 cross-spawn: regular expression denial of serviceCVE-2026-32141 flatted: flatted: Unbounded recursion DoS in parse() revive phaseCVE-2026-33228 flatted: Flatted: Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.CVE-2022-21704 log4js-node is a port of log4js to node.js. In affected versions defau ...CVE-2022-0235 node-fetch: exposure of sensitive information to an unauthorized actorCVE-2025-14874 nodemailer: Nodemailer: Denial of service via crafted email address headerGHSA-p6gq-j5cr-w38f Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered messageCVE-2021-23400 The package nodemailer before 6.6.1 are vulnerable to HTTP Header Inje ...CVE-2025-13033 nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation ConflictGHSA-268h-hp4c-crq3 Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injectionGHSA-9h6g-pr28-7cqp nodemailer ReDoS when trying to send a specially crafted emailGHSA-r7g4-qg5f-qqm2 Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential InterceptionGHSA-vvjj-xcjg-gr5g Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO) GHSA-wqvq-jvpq-h66f Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalizationCVE-2022-24999 express: "qs" prototype poisoning causes the hang of the node processCVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsingCVE-2022-25883 nodejs-semver: Regular expression denial of serviceCVE-2026-27601 Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functionsCVE-2024-37890 nodejs-ws: denial of service when handling a request with many HTTP headersCVE-2026-48779 ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsCVE-2021-32640 nodejs-ws: Specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws serverCVE-2017-16137 nodejs-debug: Regular expression Denial of ServiceYour dependencies cross-checked against the OSV vulnerability database.
GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-4cpg-3vgw-4877 Prototype pollution in Plist before 3.0.5 can cause denial of serviceGHSA-gff7-g5r8-mg8m Prototype Pollution in simple-plistGHSA-cf4h-3jhx-xvhq Arbitrary Code Execution in underscoreGHSA-crh6-fp67-6883 xmldom allows multiple root nodes in a DOMGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-93q8-gq69-wqmw Inefficient Regular Expression Complexity in chalk/ansi-regexGHSA-93q8-gq69-wqmw Inefficient Regular Expression Complexity in chalk/ansi-regexGHSA-fwr7-v2mv-hh25 Prototype Pollution in asyncGHSA-pp7h-53gx-mx7r Remote Memory Exposure in blGHSA-qwcr-r2fm-qrc7 body-parser vulnerable to denial of service when url encoding is enabledGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-grv7-fg5c-xmjg Uncontrolled resource consumption in bracesGHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawnGHSA-3xgq-45jj-v275 Regular Expression Denial of Service (ReDoS) in cross-spawnGHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phaseGHSA-rf6f-7fwh-wjgh Prototype Pollution via parse() in NodeJS flattedGHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phaseGHSA-rf6f-7fwh-wjgh Prototype Pollution via parse() in NodeJS flattedGHSA-hmw2-7cc7-3qxx form-data: CRLF injection in form-data via unescaped multipart field names and filenamesGHSA-q7cg-457f-vx79 joi has an uncaught RangeError on deeply nested input through recursive `link()` schemasCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-bundled_binary bundled_binary match in systray 1.0.5guarddog-npm-shady-links shady-links match in nodemailer 6.10.1A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 1.4/10scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Code-Review Code-Review scored 0: Found 0/30 approved changesets -- score normalized to 0scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-License License scored 0: license file not detectedscorecard-Maintained Maintained scored 0: project is archivedscorecard-SAST SAST scored 0: no SAST tool detectedscorecard-Security-Policy Security-Policy scored 0: security policy file not detectedscorecard-Signed-Releases Signed-Releases scored 0: Project has not signed or included provenance with any releases.