Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2026-54285 @opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headersCVE-2026-54285 @opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headersCVE-2026-54285 @opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headersCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesCVE-2026-44289 protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decodingCVE-2026-44290 protobufjs: protobufjs: Denial of Service via crafted schemaCVE-2026-44291 protobufjs: protobufjs: Arbitrary Code Execution via prototype pollutionCVE-2026-44293 protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptorsCVE-2026-48712 protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payloadCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesCVE-2026-44292 protobufjs: protobufjs: Data integrity impact due to prototype pollutionCVE-2026-44294 protobufjs: protobufjs: Denial of Service due to unescaped control characters in field namesCVE-2026-45740 protobufjs: protobufjs: Denial of Service via crafted JSON descriptorsCVE-2026-54269 protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpersCVE-2026-59877 protobufjs: protobufjs: Denial of Service via crafted .proto schemaYour dependencies cross-checked against the OSV vulnerability database.
GHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-f88m-g3jw-g9cj sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591GHSA-2mjp-6q6p-2qxm Undici has an HTTP Request/Response Smuggling issueGHSA-4992-7rv2-5pvq Undici has CRLF Injection in undici via `upgrade` optionGHSA-4cwx-7wf7-3272 undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesGHSA-8xcm-r25x-g524 undici vulnerable to downstream response desynchronization via retry interceptorGHSA-f269-vfmq-vjvj Undici: Malicious WebSocket 64-bit length overflows parser and crashes the clientGHSA-jr45-8vmc-qm54 undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directivesGHSA-m8rv-5g2x-5cg5 undici vulnerable to CRLF Injection via blob-like body 'type' propertyGHSA-p88m-4jfj-68fv undici vulnerable to HTTP header injection via Set-Cookie percent-decodingGHSA-phc3-fgpg-7m6h Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoSGHSA-pr7r-676h-xcf6 undici vulnerable to cross-user information disclosure via shared cache whitespace bypassGHSA-v3r7-h72x-cjcm undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fieldsGHSA-v9p9-hfj2-hcw8 Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits ValidationGHSA-vrm6-8vpv-qv8q Undici has Unbounded Memory Consumption in WebSocket permessage-deflate DecompressionGHSA-vxpw-j846-p89q undici WebSocket client vulnerable to denial of service via fragment count bypassGHSA-58qx-3vcg-4xpx ws: Uninitialized memory disclosureGHSA-96hv-2xvq-fx4p ws: Memory exhaustion DoS from tiny fragments and data chunksGHSA-8988-4f7v-96qf OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagationGHSA-8988-4f7v-96qf OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagationGHSA-28wg-ghj8-5hjv nanoid: non-secure generators can loop indefinitely with negative sizeGHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.