Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2018-16385 ThinkPHP SQL Injection vulnerabilityCVE-2021-23592 Deserialization of Untrusted Data in topthink/frameworkCVE-2021-36564 Deserialization of Untrusted Data in topthink/frameworkCVE-2022-47945 ThinkPHP Framework vulnerable to remote code executionCVE-2024-34467 ThinkPHP Cross-Site Scripting VulnerabilityYour dependencies cross-checked against the OSV vulnerability database.
GHSA-33gc-6cw9-w3g4 Deserialization of Untrusted Data in topthink/frameworkGHSA-3fpv-54ff-wqfj Deserialization of Untrusted Data in topthink/frameworkGHSA-7xfj-4jpg-58vf ThinkPHP SQLi VulnerabilityGHSA-g377-x8rg-c9mf Deserialization of Untrusted Data in topthink/frameworkGHSA-mrwc-mvr8-9xq5 ThinkPHP Path Traversal VulnerabilityGHSA-p4qr-vq2g-22wp ThinkPHP Framework vulnerable to remote code executionGHSA-q868-c4vw-qjx3 ThinkPHP5 SQL Injection vulnerabilityGHSA-qjjj-7g7h-54v3 ThinkPHP deserialization vulnerabilityGHSA-qrvj-274h-hfcg Deserialization of Untrusted Data in topthink/frameworkGHSA-vcm7-88jx-3r39 ThinkPHP SQL Injection vulnerabilityGHSA-59fh-rjq3-xq7j Thinkphp has a code logic errorGHSA-69wp-xwm7-69wm Exposure of Resource to Wrong Sphere in ThinkPHP FrameworkGHSA-969f-v7jv-pgj3 ThinkPHP Cross-Site Scripting VulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.