Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroGO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesGO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaGO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessageGO-2026-5972 Enforce maximum recursion depth in encoding/asn1GO-2026-6088 Add recursion depth guard during decode in encoding/xmlGO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/httpGO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tlsGO-2026-6091 Fix Javascript regexp context tracking in html/templateGO-2026-6218 Avoid quadratic complexity in resolvePath in net/urlCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.