Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposureCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2023-45311 Code injection in fseventsCVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template functionCVE-2022-40023 python-mako: REDoS in Lexer classCVE-2026-41205 mako: Mako: Information disclosure via path traversal vulnerabilityCVE-2026-44307 mako: Mako: Information disclosure via directory traversalCVE-2017-11424 python-jwt: Incorrect handling of PEM-encoded public keysCVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formatsCVE-2026-32597 pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)CVE-2026-48526 python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web TokensCVE-2023-37920 python-certifi: Removal of e-Tugra root certificateCVE-2021-21240 python-httplib2: Regular expression denial of service via malicious headerCVE-2026-59939 httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodiesCVE-2013-2037 python-httplib2: ssl cert incorrect error handlingCVE-2020-11078 python-httplib2: CRLF injection via an attacker controlled unescaped part of uri for httplib2.Http.request functionCVE-2024-3651 python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()CVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputsCVE-2021-26813 markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular express ...CVE-2018-5773 markdown2 is vulnerable to cross-site scriptingCVE-2020-11888 python-markdown2 through 2.3.8 allows XSS because element names are mi ...CVE-2026-30922 pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded RecursionCVE-2026-59884 python-pyasn1: pyasn1: Denial of Service via crafted BER inputCVE-2026-59885 pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIERCVE-2026-59886 pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL valuesYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2018-32 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentialGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-rq8g-5pc5-wrhr Insufficient Entropy in cryptilesGHSA-hr2v-3952-633q Prototype Pollution in deep-extendGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-957j-59c2-j692 Prototype pollution in getobjectGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-28xh-wpgr-7fm8 Command Injection in openGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-cf4h-3jhx-xvhq Arbitrary Code Execution in underscoreGHSA-xv26-6w52-cph6 websocket-driver: Message corruption via abuse of protocol length headersPYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to disPYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `reCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-bundled_binary bundled_binary match in snyk 1.1306.4guarddog-npm-npm-install-script npm-install-script match in snyk 1.1306.4A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.