Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
stripe-access-token Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2020-29582 kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosureCVE-2022-24329 kotlin: Not possible to lock dependencies for Multiplatform Gradle ProjectsCVE-2020-29582 kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosureCVE-2022-24329 kotlin: Not possible to lock dependencies for Multiplatform Gradle ProjectsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-574f-3g2m-x479 Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocksGHSA-574f-3g2m-x479 Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocksGHSA-hh32-7344-cg2f Authorization bypass in Spring SecurityGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-vmq6-5m68-f53m logback serialization vulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-pr98-23f8-jwxv QOS.CH logback-core Expression Language Injection vulnerabilityGHSA-25qh-j22f-pwp8 QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-h46c-h94j-95f3 jackson-core can throw a StackoverflowError when processing deeply nested dataGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS ConditionGHSA-r7wm-3cxj-wff9 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-5jmj-h7xm-6q6v jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnorePropertiesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.