Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2021-34371 Deserialization of Untrusted Data in Neo4jCVE-2021-35515 apache-commons-compress: infinite loop when reading a specially crafted 7Z archiveCVE-2021-35516 apache-commons-compress: excessive memory allocation when reading a specially crafted 7Z archiveCVE-2021-35517 apache-commons-compress: excessive memory allocation when reading a specially crafted TAR archiveCVE-2021-36090 apache-commons-compress: excessive memory allocation when reading a specially crafted ZIP archiveCVE-2018-11771 apache-commons-compress: ZipArchiveInputStream.read() fails to identify correct EOF allowing for DoS via crafted zipCVE-2018-1324 apache-commons-compress: Infinite loop via extra field parser in ZipFile and ZipArchiveInputStream classesCVE-2024-25710 commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP fileCVE-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons LangCVE-2026-1622 neo4j: Unredacted data exposure in query.logCVE-2026-1337 Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query logYour dependencies cross-checked against the OSV vulnerability database.
GHSA-pc4w-8v5j-29w9 Deserialization of Untrusted Data in Neo4jGHSA-pc4w-8v5j-29w9 Deserialization of Untrusted Data in Neo4jGHSA-pc4w-8v5j-29w9 Deserialization of Untrusted Data in Neo4jGHSA-pc4w-8v5j-29w9 Deserialization of Untrusted Data in Neo4jGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-4j3g-rwwq-4p54 Neo4j Enterprise and Community vulnerable to a potential information disclosureGHSA-4g9r-vxhx-9pgx Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP fileGHSA-7hfm-57qf-j43q Excessive Iteration in CompressGHSA-crv7-7245-f45f Improper Handling of Length Parameter Inconsistency in CompressGHSA-h436-432x-8fvx Apache Commons Compress vulnerable to denial of service due to infinite loopGHSA-hrmr-f5m6-m9pq Moderate severity vulnerability that affects org.apache.commons:commons-compressGHSA-mc84-pj99-q6hh Improper Handling of Length Parameter Inconsistency in CompressGHSA-xqfj-vm6h-2x34 Improper Handling of Length Parameter Inconsistency in CompressGHSA-4j3g-rwwq-4p54 Neo4j Enterprise and Community vulnerable to a potential information disclosureGHSA-4j3g-rwwq-4p54 Neo4j Enterprise and Community vulnerable to a potential information disclosureGHSA-4g9r-vxhx-9pgx Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP fileGHSA-7hfm-57qf-j43q Excessive Iteration in CompressGHSA-crv7-7245-f45f Improper Handling of Length Parameter Inconsistency in CompressGHSA-h436-432x-8fvx Apache Commons Compress vulnerable to denial of service due to infinite loopGHSA-hrmr-f5m6-m9pq Moderate severity vulnerability that affects org.apache.commons:commons-compressGHSA-mc84-pj99-q6hh Improper Handling of Length Parameter Inconsistency in CompressGHSA-xqfj-vm6h-2x34 Improper Handling of Length Parameter Inconsistency in CompressGHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-4j3g-rwwq-4p54 Neo4j Enterprise and Community vulnerable to a potential information disclosureCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.