Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-24rp-q3w6-vc56 org.postgresql:postgresql vulnerable to SQL Injection via line comment generationGHSA-24rp-q3w6-vc56 org.postgresql:postgresql vulnerable to SQL Injection via line comment generationGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-cqqj-4p63-rrmm HTTP Request Smuggling in NettyGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted DataGHSA-fjq5-5j5f-mvxh Deserialization of Untrusted Data in Apache commons collectionsGHSA-9378-f4v7-jgm4 Deserialization of Untrusted Data in org.apache.ddlutils:ddlutilsGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-6phf-73q6-gh87 Insecure Deserialization in Apache Commons BeanutilsGHSA-p66x-2cv9-qq3v Arbitrary code execution in Apache Commons BeanUtilsGHSA-wxr5-93ph-8wr9 Apache Commons Improper Access Control vulnerabilityGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-4vrv-ch96-6h42 Improper Privilege Management in MySQL Connectors JavaCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.