Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2025-43865 react-router: React Router allows pre-render data spoofing on React-Router framework modeCVE-2025-59057 react-router: @remix-run/router: React Router XSS VulnerabilityCVE-2026-21884 react-router: @remix-run/react: React Router SSR XSS in ScrollRestorationCVE-2026-22029 @remix-run/router: react-router: React Router vulnerable to XSS via Open RedirectsCVE-2026-34077 react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handlingCVE-2026-42211 react-router: React Router: Remote Code Execution via prototype pollution in Framework ModeCVE-2026-42342 react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpointCVE-2026-55685 react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requestsCVE-2025-68470 react-router: React Router unexpected external redirectCVE-2026-22030 react-router: React Router CSRF in Action/Server Action Request ProcessingCVE-2026-40181 react-router: React Router: Open redirect vulnerability via specially crafted URLsCVE-2026-53666 react-router: React Router: Information disclosure via client-side constructor executionCVE-2026-53669 react-router: React Router: Open Redirect vulnerability via backslashes in navigation componentsCVE-2026-34077 react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handlingYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67mh-4wv8-2f99 esbuild enables any website to send any requests to the development server and read the responseGHSA-2j2x-hqr9-3h42 React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretationGHSA-2w69-qvjg-hvjx React Router vulnerable to XSS via Open RedirectsGHSA-337j-9hxr-rhxg React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR HydrationGHSA-3cgp-3xvw-98x8 React Router has XSS VulnerabilityGHSA-49rj-9fvp-4h2h React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCEGHSA-8v8x-cx79-35w7 React Router SSR XSS in ScrollRestorationGHSA-8x6r-g9mw-2r78 React Router vulnerable to DoS via unbounded path expansion in __manifest endpointGHSA-9jcx-v3wj-wh4m React Router has unexpected external redirect via untrusted pathsGHSA-chx6-hx7r-mcp5 React Router: Unauthenticated Denial of Service via Inefficient Route MatchingGHSA-cpj6-fhp6-mr6j React Router allows pre-render data spoofing on React-Router framework modeGHSA-h5cw-625j-3rxh React Router has CSRF issue in Action/Server Action Request ProcessingGHSA-rxv8-25v2-qmq8 React Router vulnerable to Denial of Service via reflected user input in single-fetchGHSA-wrjc-x8rr-h8h6 React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)GHSA-rxv8-25v2-qmq8 React Router vulnerable to Denial of Service via reflected user input in single-fetchCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.