Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
Nothing found by this check. ✓
Your dependencies cross-checked against the OSV vulnerability database.
GHSA-2x83-r56g-cv47 Improper certificate validation in org.apache.httpcomponents:httpclientGHSA-7r82-7xv7-xcpj Cross-site scripting in Apache HttpClientGHSA-3vqj-43w4-2q58 json stack overflow vulnerabilityGHSA-4jq9-2xhw-jpx7 Java: DoS Vulnerability in JSON-JAVAGHSA-2x83-r56g-cv47 Improper certificate validation in org.apache.httpcomponents:httpclientGHSA-7r82-7xv7-xcpj Cross-site scripting in Apache HttpClientGHSA-3vqj-43w4-2q58 json stack overflow vulnerabilityGHSA-4jq9-2xhw-jpx7 Java: DoS Vulnerability in JSON-JAVAGHSA-cfh5-3ghh-wfjx Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclientGHSA-fmj5-wv96-r2ch Denial of service vulnerability in org.apache.httpcomponents:httpclientGHSA-gw85-4gmf-m7rh Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClientGHSA-cfh5-3ghh-wfjx Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclientGHSA-fmj5-wv96-r2ch Denial of service vulnerability in org.apache.httpcomponents:httpclientGHSA-gw85-4gmf-m7rh Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClientCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.