Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2021-46743 Key/algorithm type confusionGHSA-qm5c-m76r-2hfr Laravel RCE vulnerability in "cookie" session driverCVE-2024-28859 Deserialization Gadget chain in Swift MailerCVE-2019-10913 In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...CVE-2024-51736 CVE-2024-51736: Command execution hijack on Windows with Process classCVE-2023-45133 babel: arbitrary code executionCVE-2018-9206 Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery- ...CVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2023-45311 Code injection in fseventsCVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerabilityCVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying propertiesGHSA-27qh-8cxx-2cr5 AWS SDK for PHP has CloudFront Policy Document Injection via Special CharactersCVE-2025-14761 Key Commitment Issues in S3 Encryption ClientsCVE-2019-10905 Class-Name InjectionCVE-2018-1000162 Cross-Site ScriptingCVE-2022-29248 Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 ...CVE-2022-31042 Guzzle is an open source PHP HTTP client. In affected versions the `Co ...CVE-2022-31043 Guzzle is an open source PHP HTTP client. In affected versions `Author ...CVE-2022-31090 Guzzle, an extensible PHP HTTP client. `Authorization` headers on requ ...CVE-2022-31091 Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` he ...CVE-2026-69246 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...CVE-2026-55568 Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain c ...CVE-2026-55767 Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar in ...CVE-2026-59883 guzzle/guzzle: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar.CVE-2026-67339 guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-8xf4-w7qw-pjjw Firebase PHP-JWT key/algorithm type confusionGHSA-qm5c-m76r-2hfr Laravel RCE vulnerability in "cookie" session driverGHSA-9f46-5r25-5wfm Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystemGHSA-x92h-wmg2-6hp7 Invalid HTTP method overrides allow possible XSS or other attacks in SymfonyGHSA-8w4h-3cm3-2pm2 Out-of-bounds Read in atobGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-4cj8-g9cp-v5wr Unrestricted Upload of File with Dangerous Type in blueimp-file-uploadGHSA-cpq7-6gpm-g9rc cipher-base is missing type checks, leading to hash rewind and passing on crafted dataGHSA-mp2f-45pm-3cg9 Decompress: Archive extraction can create files and links outside of the target directoryGHSA-qgfr-5hqp-vrw9 Path Traversal in decompressGHSA-hr2v-3952-633q Prototype Pollution in deep-extendGHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)GHSA-6h5x-7c5m-7cr7 Exposure of Sensitive Information in eventsourceGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryMAL-2023-462 Malicious code in fsevents (npm)GHSA-8r6j-v8pm-fqw3 Code injection in fseventsGHSA-896r-f27r-55mw json-schema is vulnerable to Prototype PollutionGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsGHSA-76p3-8jx3-jpfq Prototype pollution in webpack loader-utilsGHSA-jf85-cpcp-j695 Prototype Pollution in lodashGHSA-pp57-mqmh-44h7 Command Injection in macaddressGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-xvch-5gv4-984h Prototype Pollution in minimistGHSA-92xj-mqp7-vmcj Prototype Pollution in node-forgeGHSA-h7cp-r72f-jxh6 pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algosCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.