Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2022-39135 calcite: XXE via SQL operatorsCVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeperCVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeperCVE-2024-1597 pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLECVE-2024-1597 pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLECVE-2024-1597 pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLECVE-2019-20444 netty: HTTP request smugglingCVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeperCVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserializationCVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)CVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeperCVE-2023-45311 Code injection in fseventsCVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesYour dependencies cross-checked against the OSV vulnerability database.
GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4jGHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.xGHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4jGHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-r7pg-v2c8-mfg3 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)GHSA-r7pg-v2c8-mfg3 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)GHSA-r7pg-v2c8-mfg3 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-cpq7-6gpm-g9rc cipher-base is missing type checks, leading to hash rewind and passing on crafted dataGHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)MAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-fhjf-83wg-r2j9 Prototype Pollution in mixin-deepGHSA-h7cp-r72f-jxh6 pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algosGHSA-v62p-rq8g-8h59 pbkdf2 silently disregards Uint8Array input, returning static keysCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.