Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-5gvw-p9qm-jgwh jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserializationGHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-54fx-42gc-7vw4 Hono: Algorithmic Complexity DoS in Language MiddlewareGHSA-8j4g-w8fx-2239 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersGHSA-f23p-vx2j-j53r Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureGHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroGHSA-79qm-7rj5-m7r9 Hono: Proxy Helper does not remove response headers listed in the `Connection` headerCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.