Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2024-36039 python-pymysql: SQL injection if used with untrusted JSON inputCVE-2017-18342 PyYAML: yaml.load() API could execute arbitrary codeCVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747CVE-2019-7164 python-sqlalchemy: SQL Injection when the order_by parameter can be controlledCVE-2019-7548 python-sqlalchemy: SQL Injection when the group_by parameter can be controlledCVE-2024-36039 python-pymysql: SQL injection if used with untrusted JSON inputCVE-2018-7750 python-paramiko: Authentication bypass in transport.pyCVE-2017-18342 PyYAML: yaml.load() API could execute arbitrary codeCVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747CVE-2019-7164 python-sqlalchemy: SQL Injection when the order_by parameter can be controlledCVE-2019-7548 python-sqlalchemy: SQL Injection when the group_by parameter can be controlledCVE-2018-17175 In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Py ...CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.pyCVE-2018-1000807 pyOpenSSL: Use-after-free in X509 object handlingCVE-2018-1000808 pyOpenSSL: Failure to release memory before removing last reference in PKCS #12 StoreCVE-2013-6418 pywbem: TOCTOU vulnerability in certificate validationCVE-2013-6444 pywbem: failure to check certificate hostnameCVE-2026-27448 pyOpenSSL: TLS connection bypass via unhandled callback exception in set_tlsext_servername_callbackYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.