Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonCVE-2018-8292 Core: information disclosure due to authentication information exposed in a redirectCVE-2019-0820 dotnet: timeouts for regular expressions are not enforcedCVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonCVE-2018-8292 Core: information disclosure due to authentication information exposed in a redirectCVE-2019-0820 dotnet: timeouts for regular expressions are not enforcedCVE-2018-8269 Denial of service in ASP.NET CoreCVE-2020-1045 dotnet: ASP.NET cookie prefix spoofing vulnerabilityCVE-2022-29117 dotnet: malicious content causes high CPU and memory usageCVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonCVE-2018-8292 Core: information disclosure due to authentication information exposed in a redirectCVE-2019-0820 dotnet: timeouts for regular expressions are not enforcedYour dependencies cross-checked against the OSV vulnerability database.
GHSA-5crp-9r3c-p9vr Improper Handling of Exceptional Conditions in Newtonsoft.JsonGHSA-7jgj-8wvc-jh57 .NET Core Information DisclosureGHSA-cmhx-cq75-c4mj Regular Expression Denial of Service in System.Text.RegularExpressionsGHSA-5crp-9r3c-p9vr Improper Handling of Exceptional Conditions in Newtonsoft.JsonGHSA-7jgj-8wvc-jh57 .NET Core Information DisclosureGHSA-cmhx-cq75-c4mj Regular Expression Denial of Service in System.Text.RegularExpressionsGHSA-mv2r-q4g5-j8q5 Denial of service in ASP.NET CoreGHSA-3rq8-h3gj-r5c6 .NET Denial of Service VulnerabilityGHSA-hxrm-9w7p-39cc Cookie parsing failureGHSA-5crp-9r3c-p9vr Improper Handling of Exceptional Conditions in Newtonsoft.JsonGHSA-7jgj-8wvc-jh57 .NET Core Information DisclosureGHSA-cmhx-cq75-c4mj Regular Expression Denial of Service in System.Text.RegularExpressionsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.