Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-24163 Dromara hutool vulnerable to SQL InjectionCVE-2017-15095 jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525)CVE-2017-17485 jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095)CVE-2017-7525 jackson-databind: Deserialization vulnerability via readValue method of ObjectMapperCVE-2018-11307 jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatisCVE-2018-14718 jackson-databind: arbitrary code execution in slf4j-ext classCVE-2018-14719 jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classesCVE-2018-19362 jackson-databind: improper polymorphic deserialization in jboss-common-core classCVE-2018-7489 jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 librariesCVE-2019-14379 jackson-databind: default typing mishandling leading to remote code executionCVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfigCVE-2019-16335 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSourceCVE-2019-16942 jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.*CVE-2019-16943 jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSourceCVE-2019-17267 jackson-databind: Serialization gadgets in classes of the ehcache packageCVE-2019-17531 jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*CVE-2019-20330 jackson-databind: lacks certain net.sf.ehcache blockingCVE-2020-8840 jackson-databind: Lacks certain xbean-reflect/JNDI blockingCVE-2020-9547 jackson-databind: Serialization gadgets in ibatis-sqlmapCVE-2020-9548 jackson-databind: Serialization gadgets in anteros-coreCVE-2022-42889 apache-commons-text: variable interpolation RCECVE-2025-14813 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctlyCVE-2022-25845 fastjson: autoType shutdown restriction bypass leads to deserializationCVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowErrorGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)Your dependencies cross-checked against the OSV vulnerability database.
GHSA-6c25-cxcc-pmc4 Dromara hutool vulnerable to SQL InjectionGHSA-77h8-5j3h-jcjf Dromara Hutool Deserialization of Untrusted Data vulnerabilityGHSA-pv7h-hx5h-mgfj Unsafe deserialization in com.alibaba:fastjsonGHSA-pfh2-hfmq-phg5 json-path Out-of-bounds Write vulnerabilityGHSA-4vrv-ch96-6h42 Improper Privilege Management in MySQL Connectors JavaGHSA-g76j-4cxx-23h9 Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors JavaGHSA-jcq3-cprp-m333 Privilege escalation in mysql-connector-javGHSA-m6vm-37g8-gqvh MySQL Connectors takeover vulnerabilityGHSA-gmg8-593g-7mv3 Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File ParsingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.