Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesCVE-2024-21508 mysql2: Remote Code ExecutionCVE-2024-21511 mysql2: Arbitrary Code Injection due to improper sanitization of the timezone parameterCVE-2019-10748 SQL Injection in sequelizeCVE-2019-10752 SQL Injection in sequelizeCVE-2023-22578 Sequelize - Default support for “raw attributes” when using parenthesesCVE-2023-22579 Unsafe fall-through in getWhereConditionsCVE-2023-25813 Sequelize vulnerable to SQL Injection via replacementsCVE-2026-69240 sequelize: Sequelize: SQL Injection via improper handling of Oracle date functionsCVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parserCVE-2023-26132 Versions of the package dottie before 2.0.4 are vulnerable to Prototyp ...CVE-2024-29041 express: cause malformed URLs to be evaluatedCVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep functionCVE-2021-23337 nodejs-lodash: command injection via templateCVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template importsCVE-2020-28500 nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functionsCVE-2025-13465 lodash: prototype pollution in _.unset and _.omit functionsCVE-2026-2950 lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypassCVE-2022-24785 Moment.js: Path traversal in moment.localeCVE-2022-31129 moment: inefficient parsing algorithm resulting in DoSGHSA-v78c-4p63-2j6c Cleartext Transmission of Sensitive Information in moment-timezoneCVE-2024-21512 mysql2: vulnerable to Prototype Pollution due to improper user input sanitizationCVE-2024-21507 mysql2: Improper Input ValidationCVE-2024-21509 mysql2: Prototype PoisoningCVE-2024-45296 path-to-regexp: Backtracking regular expressions cause ReDoSYour dependencies cross-checked against the OSV vulnerability database.
GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-fhjf-83wg-r2j9 Prototype Pollution in mixin-deepGHSA-4rch-2fh8-94vw MySQL2 for Node Arbitrary Code InjectionGHSA-fpw7-j2hg-69v5 mysql2 Remote Code Execution (RCE) via the readCodeFor functionGHSA-f598-mfpv-gmfx Sequelize - Default support for “raw attributes” when using parenthesesGHSA-j9xp-92vc-559j SQL Injection in sequelizeGHSA-m9jw-237r-gvfv SQL Injection in sequelizeGHSA-v8fg-2rw7-q452 Sequelize: SQL Injection (Oracle DB)GHSA-vqfx-gj96-3w95 Unsafe fall-through in getWhereConditionsGHSA-wrh9-cjv3-2hpw Sequelize vulnerable to SQL Injection via replacementsGHSA-4g88-fppr-53pp Prototype Pollution in set-valueGHSA-4g88-fppr-53pp Prototype Pollution in set-valueGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsGHSA-93q8-gq69-wqmw Inefficient Regular Expression Complexity in chalk/ansi-regexGHSA-qwcr-r2fm-qrc7 body-parser vulnerable to denial of service when url encoding is enabledGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-npm-install-script npm-install-script match in nodemon 1.18.11A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.