Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2018-3750 nodejs-deep-extend: Prototype pollution can allow attackers to modify object propertiesCVE-2021-44906 minimist: prototype pollutionCVE-2021-44906 minimist: prototype pollutionCVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leakedCVE-2020-7788 nodejs-ini: Prototype pollution via malicious INI fileCVE-2020-7598 nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payloadCVE-2020-7598 nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payloadCVE-2022-25883 nodejs-semver: Regular expression denial of serviceCVE-2022-0355 simple-get: exposure of sensitive information to an unauthorized actorCVE-2018-20835 Improper Input Validation in tar-fsCVE-2024-12905 tar-fs: link following and path traversal via maliciously crafted tar fileCVE-2025-48387 tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarballCVE-2025-59343 tar-fs: tar-fs symlink validation bypassCVE-2017-18869 nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.jsNSWG-ECO-408 deep-extend prototype pollutionYour dependencies cross-checked against the OSV vulnerability database.
GHSA-hr2v-3952-633q Prototype Pollution in deep-extendGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-pp7h-53gx-mx7r Remote Memory Exposure in blGHSA-qqgx-2p2h-9c37 ini before 1.3.6 vulnerable to Prototype Pollution via ini.parseGHSA-vh95-rmgr-6w4m Prototype Pollution in minimistGHSA-vh95-rmgr-6w4m Prototype Pollution in minimistGHSA-c2qf-rxjj-qqgw semver vulnerable to Regular Expression Denial of ServiceGHSA-wpg7-2c88-r8xv Exposure of Sensitive Information in simple-getGHSA-8cj5-5rvv-wf4v tar-fs can extract outside the specified dir with a specific tarballGHSA-pq67-2wwv-3xjx tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar FileGHSA-vj76-c3g6-qr5v tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarballGHSA-x2mc-8fgj-3wmr Improper Input Validation in tar-fsGHSA-c6rq-rjc2-86v2 Time-of-check Time-of-use (TOCTOU) Race Condition in chownrCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
guarddog-npm-npm-install-script npm-install-script match in node-hid 0.7.9A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.