Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-47554 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReaderCVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIsCVE-2022-45688 json stack overflow vulnerabilityCVE-2023-5072 JSON-java: parser confusion leads to OOMYour dependencies cross-checked against the OSV vulnerability database.
GHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReaderGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-683x-4444-jxh8 Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-javaGHSA-6fhj-vr9j-g45r CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection GHSA-h46c-h94j-95f3 jackson-core can throw a StackoverflowError when processing deeply nested dataGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-3wrr-7qpf-2prh jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()GHSA-57j2-w4cx-62h2 Deeply nested json in jackson-databindGHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesGHSA-hgj6-7826-r7m5 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)GHSA-j3rv-43j4-c7qm jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiationGHSA-jjjh-jjxp-wpff Uncontrolled Resource Consumption in Jackson-databindGHSA-rgv9-q543-rqg4 Uncontrolled Resource Consumption in FasterXML jackson-databindGHSA-rmj7-2vxq-3g9f jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)GHSA-3f7h-mf4q-vrm4 Denial of Service due to parser crashGHSA-7r82-7xv7-xcpj Cross-site scripting in Apache HttpClientGHSA-3vqj-43w4-2q58 json stack overflow vulnerabilityGHSA-4jq9-2xhw-jpx7 Java: DoS Vulnerability in JSON-JAVACode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.