Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2026-26007 cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT CurvesGHSA-537c-gmf6-5ccf Vulnerable OpenSSL included in cryptography wheelsGHSA-h4gh-qq45-vh27 pyca/cryptography has a vulnerable OpenSSL included in cryptography wheelsCVE-2026-34531 Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication fo ...CVE-2025-66034 fonttools: fontTools: Arbitrary file write leading to remote code execution via malicious .designspace fileCVE-2026-42215 GitPython is a python library used to interact with Git repositories. ...CVE-2026-42284 GitPython is a python library used to interact with Git repositories. ...CVE-2026-44243 GitPython: GitPython: Arbitrary file write via crafted reference pathsCVE-2026-44244 GitPython is a python library used to interact with Git repositories. ...GHSA-mv93-w799-cj2w GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPathCVE-2026-45409 Internationalized Domain Names in Applications (IDNA) for Python provi ...CVE-2024-56201 jinja2: Jinja has a sandbox breakout through malicious filenamesCVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format methodCVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format methodCVE-2025-68480 github.com/marshmallow-code/marshmallow: Marshmallow: Denial of Service via crafted request to Schema.load functionCVE-2026-25990 pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD ImageCVE-2026-40192 Pillow: Pillow: Denial of Service via decompression bomb in FITS image processingCVE-2026-42311 Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processingCVE-2026-42308 Pillow: python: Pillow: Denial of Service via integer overflow in font processingCVE-2026-42310 Pillow: Pillow: Denial of Service via malicious PDF processingCVE-2026-32597 pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)CVE-2026-48526 python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web TokensCVE-2026-48522 python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClientCVE-2026-48523 python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information accessCVE-2026-48525 python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokensYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 4.3/10scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0scorecard-SAST SAST scored 0: SAST tool is not run on all commits -- score normalized to 0scorecard-Security-Policy Security-Policy scored 0: security policy file not detectedscorecard-Token-Permissions Token-Permissions scored 0: detected GitHub workflow tokens with excessive permissions