Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
PYSEC-2016-32 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.PYSEC-2016-32 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.PYSEC-2020-213 Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determinPYSEC-2023-75 Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user accePYSEC-2025-265 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injePYSEC-2025-266 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, PYSEC-2025-267 Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. PYSEC-2026-140 Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting PYSEC-2026-1974 Tornado vulnerable to excessive logging caused by malformed multipart form dataPYSEC-2026-1975 Tornado has an HTTP cookie parsing DoS vulnerabilityPYSEC-2026-2287 In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.PYSEC-2026-3387 Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClientPYSEC-2026-3389 tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)GHSA-753j-mpmx-qq6g Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornadoGHSA-pw6j-qg29-8w7f Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuseGHSA-w235-7p84-xx57 Tornado has a CRLF injection in CurlAsyncHTTPClient headersPYSEC-2022-43017 An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.PYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to disPYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rePYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLsPYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=FalsePYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system tePYSEC-2019-217 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.PYSEC-2019-220 In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.