Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
GHSA-xhj4-vrgc-hr34 actix-http has HTTP/1.1 CL.TE Request Smuggling GHSA-h5x4-m2qf-r4f2 Diesel's SQLite backend has possible UTF-8 corruptionGHSA-ggxf-9f6j-w742 Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`GHSA-m9p2-fxp5-v3fp Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`GHSA-q8x8-jrhj-fh9p Diesel: Possible unaligned data access for implementations of `SqliteAggregate`CVE-2026-42327 rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificateCVE-2026-44662 rust-openssl provides OpenSSL bindings for the Rust programming langua ...CVE-2026-45784 rust-openssl: rust-openssl: Heap Corruption from Incorrect Buffer SizingGHSA-4w2j-m93h-cj5j Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblyGHSA-82j2-j2ch-gfr8 rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGGHSA-7gcf-g7xr-8hxj serde_with: KeyValueMap serialization panics on empty sequence or map entriesGHSA-3pv8-6f4r-ffg2 tar has a PAX header desynchronization issueGHSA-8v4j-7jgf-5rg9 Warp vulnerable to Path Traversal via Improper validation of Windows pathsCVE-2022-35922 Rust-WebSocket memory allocation based on untrusted lengthGHSA-cq8v-f236-94qc Rand is unsound with a custom logger using rand::rng()GHSA-cq8v-f236-94qc Rand is unsound with a custom logger using rand::rng()GHSA-965h-392x-2mh5 webpki: Name constraints for URI names were incorrectly acceptedGHSA-xgp8-3hg3-c2mh webpki: Name constraints were accepted for certificates asserting a wildcard nameYour dependencies cross-checked against the OSV vulnerability database.
GHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-xhj4-vrgc-hr34 actix-http has HTTP/1.1 CL.TE Request Smuggling RUSTSEC-2026-0111 Possible UTF-8 corruption in Diesels SQLite backendRUSTSEC-2026-0136 Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`RUSTSEC-2026-0137 Possible unaligned data access for implementations of `SqliteAggregate`RUSTSEC-2026-0172 Possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`GHSA-phqj-4mhp-q6mq rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersGHSA-xp3w-r5p5-63rr rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsGHSA-xv59-967r-8726 rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-paddingRUSTSEC-2026-0194 Quadratic run time when checking a start tag for duplicate attribute namesRUSTSEC-2026-0195 Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of serviceRUSTSEC-2026-0194 Quadratic run time when checking a start tag for duplicate attribute namesRUSTSEC-2026-0195 Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of serviceRUSTSEC-2026-0185 Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblyRUSTSEC-2026-0189 DNS rebinding vulnerability in rmcp Streamable HTTP server transportRUSTSEC-2026-0104 Reachable panic in certificate revocation list parsingGHSA-7gcf-g7xr-8hxj serde_with: KeyValueMap serialization panics on empty sequence or map entriesRUSTSEC-2022-0035 Unbounded memory allocation based on untrusted lengthGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-v56q-mh7h-f735 Immutable.js `List` 32-bit trie overflow → unrecoverable DoSGHSA-xvcm-6775-5m9r Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetGHSA-52cp-r559-cp3m js-yaml: YAML merge-key chains can force quadratic CPU consumptionGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.