Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2021-45688 Use of Uninitialized Resource in ash.CVE-2021-32619 Deno's static imports inside dynamically imported modules do not adhere to permission checksCVE-2026-22863 Deno node:crypto doesn't finalize cipherGHSA-qj69-c89v-jwq2 Reading on uninitialized memory may cause UB ( `util::read_spv()` )GHSA-f85w-wvc7-crwc bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`CVE-2022-23639 crossbeam-utils provides atomics, synchronization primitives, scoped t ...CVE-2021-41641 Link Following in DenoCVE-2023-28446 Interactive `run` permission prompt spoofing via improper ANSI neutralizationCVE-2024-34346 Deno permission escalation vulnerability via open of privileged files with missing `--deny` flagCVE-2025-21620 fetch: Authorization headers not dropped when redirecting cross-originCVE-2025-61787 Deno is Vulnerable to Command Injection on Windows During Batch File ExecutionCVE-2026-22864 Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypassCVE-2026-27190 Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_processCVE-2026-49401 Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)CVE-2026-49402 Deno: Command Injection via spawnSync & spawn on WindowsCVE-2026-49440 Deno: Miller-Rabin Primality Test Allows Zero RoundsCVE-2024-21486 Deno vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2024-27931 Insufficient permission checking in `Deno.makeTemp*` APIsCVE-2024-27932 Deno's improper suffix match testing for DENO_AUTH_TOKENSCVE-2025-48934 Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesCVE-2026-49406 Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictionsCVE-2026-49411 Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checksCVE-2026-49859 Deno: `fetch()` API sandbox bypass via missing DNS resolution checkCVE-2026-49860 Deno: WebSocket API sandbox bypass via missing post-DNS checkCVE-2026-49983 Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read accessYour dependencies cross-checked against the OSV vulnerability database.
RUSTSEC-2021-0065 anymap is unmaintained.RUSTSEC-2021-0090 Reading on uninitialized memory may cause UB ( `util::read_spv()` )GHSA-5379-f5hf-w38v Deno node:crypto doesn't finalize cipherGHSA-xpwj-7v8q-mcgj Deno's static imports inside dynamically imported modules do not adhere to permission checksRUSTSEC-2021-0091 Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )RUSTSEC-2021-0079 Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data lossRUSTSEC-2022-0041 Unsoundness of AtomicCell<*64> arithmetics on 32-bit targets that support Atomic*64GHSA-23rx-c3g5-hv9w Deno permission escalation vulnerability via open of privileged files with missing `--deny` flagGHSA-4c8g-jvcx-v4hv Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read accessGHSA-5frw-4rwq-xhcr Deno's improper suffix match testing for DENO_AUTH_TOKENSGHSA-67hm-27mx-9cg7 Link Following in DenoGHSA-7w8p-chxq-2789 Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesGHSA-7xh3-mhg9-jcw8 Deno: Command Injection via spawnSync & spawn on WindowsGHSA-83pc-3rw9-qpwj Deno: WebSocket API sandbox bypass via missing post-DNS checkGHSA-8xpq-cjcf-3wh9 Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)GHSA-968w-xfqw-vp9q Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictionsGHSA-9xg4-qhm4-g43w Deno: Miller-Rabin Primality Test Allows Zero RoundsGHSA-cpgj-f7g3-2pp2 Deno: `fetch()` API sandbox bypass via missing DNS resolution checkGHSA-f27p-cmv8-xhm6 fetch: Authorization headers not dropped when redirecting cross-originGHSA-hmh4-3xvx-q5hr Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_processGHSA-hrqr-jv8w-v9jh Insufficient permission checking in `Deno.makeTemp*` APIsGHSA-jv4x-jv3h-qff5 Deno vulnerable to Exposure of Sensitive Information to an Unauthorized ActorGHSA-m2gf-x3f6-8hq3 Deno is Vulnerable to Command Injection on Windows During Batch File ExecutionGHSA-m3c4-prhw-mrx6 Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypassGHSA-v8fw-85r8-5m23 Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checksCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.