Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-45047 Svelte has a potential mXSS vulnerability due to improper HTML escapingCVE-2026-27121 svelte: Svelte affected by cross-site scripting via spread attributes in Svelte SSRCVE-2026-27122 svelte: Svelte SSR does not validate dynamic element tag names in `<svelte:element>`CVE-2026-27125 svelte: Svelte SSR attribute spreading includes inherited properties from prototype chainCVE-2026-27901 svelte: Svelte: Cross-Site Scripting and HTML injection via improper escaping of bind:innerText and bind:textContentCVE-2026-42573 svelte: Svelte: Cross-Site Scripting via DOM ClobberingCVE-2026-42599 svelte: Svelte: Cross-Site Scripting via untrusted data in spread attributesCVE-2025-22869 golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/sshCVE-2025-47913 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESSCVE-2026-39828 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissionsCVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parametersCVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responsesCVE-2026-39831 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence checkCVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictionsCVE-2026-39835 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificateCVE-2026-42508 golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKeyCVE-2026-46595 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validationCVE-2026-46597 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputsCVE-2025-47914 golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messagesCVE-2025-58181 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authenticationCVE-2026-39827 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openingsCVE-2026-39833 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmationCVE-2026-39834 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel writeCVE-2026-46598 golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed inputCVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site ScriptingYour dependencies cross-checked against the OSV vulnerability database.
GO-2026-5005 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentGO-2026-5006 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentGO-2026-5017 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshGO-2026-5019 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshGO-2026-5020 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshGO-2026-5021 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsGO-2026-5023 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-67mh-4wv8-2f99 esbuild enables any website to send any requests to the development server and read the responseGHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureGHSA-8266-84wp-wv5c Svelte has a potential mXSS vulnerability due to improper HTML escapingGHSA-crpf-4hrx-3jrp Svelte SSR attribute spreading includes inherited properties from prototype chainGHSA-f7gr-6p89-r883 Svelte affected by cross-site scripting via spread attributes in Svelte SSRGHSA-m56q-vw4c-c2cp Svelte SSR does not validate dynamic element tag names in `<svelte:element>`GHSA-phwv-c562-gvmh Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`GHSA-pr6f-5x2q-rwfp Svelte SSR vulnerable to cross-site scripting via spread attributesGHSA-rcqx-6q8c-2c42 Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework StateGHSA-356w-63v5-8wf4 Vite has an `server.fs.deny` bypass with an invalid `request-target`GHSA-4r4m-qw57-chr8 Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryGHSA-4w7w-66w2-5vf9 Vite Vulnerable to Path Traversal in Optimized Deps `.map` HandlingGHSA-859w-5945-r5v3 Vite's server.fs.deny bypassed with /. for files under project rootGHSA-93m4-6634-74q7 vite allows server.fs.deny bypass via backslash on WindowsGHSA-c27g-q93r-2cwf launch-editor vulnerable to command injection via the crafted request on WindowsGHSA-fx2h-pf6j-xcff vite: `server.fs.deny` bypass on Windows alternate pathsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.