Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2015-8857 The uglify-js package before 2.4.24 for Node.js does not properly acco ...CVE-2020-26238 cron-utils: template injection allows attackers to inject arbitrary Java EL expressions leading to remote code executionCVE-2021-41269 cron-utils: template Injection leading to unauthenticated Remote Code ExecutionCVE-2019-17640 Path Traversal in Eclipse VertCVE-2019-17640 Path Traversal in Eclipse VertCVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityCVE-2025-24813 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTCVE-2026-41293 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validatedCVE-2026-43512 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authenticationCVE-2026-43515 tomcat-coyote: tomcat: Improper Authorization allows security bypassCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2020-8130 rake: OS Command Injection via egrep in Rake::FileListCVE-2025-66035 angular: Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsCVE-2026-50170 @angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCacheCVE-2026-50171 @angular/common: Angular @angular/common: Denial of Service via malformed digitsInfo parameterCVE-2026-54266 @angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State PoisoningCVE-2026-54268 @angular/common: Angular @angular/common: Denial of Service via crafted date format stringCVE-2026-68945 @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCacheCVE-2025-66412 angular: Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML AttributesCVE-2026-22610 angular: Angular: Cross-site scripting vulnerability in Template CompilerCVE-2026-69151 @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlersCVE-2026-50557 @angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)Your dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.