Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2023-52892 In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, ...CVE-2026-32935 phpseclib is a PHP secure communications library. Projects using versi ...CVE-2026-44167 phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0 ...CVE-2024-27354 An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0 ...CVE-2024-27355 An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0 ...CVE-2026-55599 phpseclib is a PHP secure communications library. From 0.1.1 until 1.0 ...CVE-2025-64500 Symfony is a PHP framework for web and console applications and a set ...CVE-2024-50345 symfony/http-foundation is a module for the Symphony PHP framework whi ...CVE-2026-45067 ### Description `Symfony\Component\Mime\Address` is the value-object ...CVE-2026-45070 Symfony is a PHP framework for web and console applications and a set ...CVE-2026-40194 phpseclib is a PHP secure communications library. Starting in 0.1.1 an ...CVE-2026-46644 Symfony Polyfill backports PHP features and provides compatibility lay ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-2528-jw5q-ww88 phpseclib: guardrails needed on isPrime and randomPrimeGHSA-3qpq-r242-jqj7 phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()GHSA-94g3-g5v7-q4jg phpseclib's AES-CBC unpadding susceptible to padding oracle timing attackGHSA-f2qx-66wf-wvvx phpseclib guardrails needed on OID lengthGHSA-ff7q-6vwh-v9m4 Name confusion in x509 Subject Alternative Name fieldsGHSA-m557-wrgg-6rp4 phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information AccessGHSA-vvj3-c3rp-c85p PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage HandlingGHSA-3rg7-wf37-54rm Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypassGHSA-qpmx-3rfj-7rhv Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\AddressGHSA-vqc8-7275-q272 Symfony has Email Header Injection via Non-Token Characters in Mime Parameter NamesGHSA-r854-jrxh-36qx phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()GHSA-mrqx-rp3w-jpjp Symfony vulnerable to open redirect via browser-sanitized URLsGHSA-2xf4-cg6j-vhgq symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded formCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.