Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-34987 wasmtime: bytecodealliance/wasmtime: Wasmtime: Arbitrary code execution via incorrect memory offset handling in Winch compilerCVE-2026-24116 Wasmtime is a runtime for WebAssembly. Starting in version 29.0.0 and ...CVE-2026-27204 wasmtime: Wasmtime: Denial of Service via guest-controlled resource exhaustion in WASI host interfacesCVE-2026-27572 wasmtime: Wasmtime: Denial of Service via excessive HTTP header fieldsCVE-2026-34941 wasmtime: Wasmtime: Denial of Service and potential information disclosure via incorrect UTF-16 string validationCVE-2026-34942 wasmtime: Wasmtime: Denial of Service via improper string alignment verificationCVE-2026-34943 Wasmtime: Wasmtime: Denial of Service due to malformed flags-typed component model value processingCVE-2026-34944 wasmtime: Wasmtime: Denial of Service due to out-of-bounds read during WebAssembly compilationCVE-2026-34946 wasmtime: Wasmtime: Denial of Service via WebAssembly compilation errorCVE-2026-35186 Wasmtime: github.com/bytecodealliance/wasmtime: Wasmtime: Denial of Service and potential information disclosure via Winch compiler type confusionCVE-2026-35195 Wasmtime: Wasmtime: Data corruption and potential arbitrary code execution via unvalidated memory reallocationCVE-2025-64345 wasmtime: Wasmtime unsound API access to shared linear memoryCVE-2026-34945 wasmtime: winch: Wasmtime Winch compiler: Information disclosure via incorrect table.size instruction translationCVE-2026-34988 wasmtime: Wasmtime: Information disclosure due to improper memory handling in pooling allocatorYour dependencies cross-checked against the OSV vulnerability database.
RUSTSEC-2026-0095 Wasmtime with Winch compiler backend may allow a sandbox-escaping memory accessRUSTSEC-2026-0096 Miscompiled guest heap access enables sandbox escape on aarch64 CraneliftRUSTSEC-2026-0194 Quadratic run time when checking a start tag for duplicate attribute namesRUSTSEC-2026-0195 Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of serviceRUSTSEC-2026-0194 Quadratic run time when checking a start tag for duplicate attribute namesRUSTSEC-2026-0195 Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of serviceRUSTSEC-2023-0071 Marvin Attack: potential key recovery through timing sidechannelsRUSTSEC-2026-0006 Wasmtime segfault or unused out-of-sandbox load with `f64.copysign` operator on x86-64RUSTSEC-2026-0020 Guest-controlled resource exhaustion in WASI implementationsRUSTSEC-2026-0021 Panic adding excessive fields to a `wasi:http/types.fields` instanceRUSTSEC-2026-0085 Panic when lifting `flags` component valueRUSTSEC-2026-0086 Host data leakage with 64-bit tables and WinchRUSTSEC-2026-0087 Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on Cranelift x86-64RUSTSEC-2026-0089 Host panic when Winch compiler executes `table.fill`RUSTSEC-2026-0091 Out-of-bounds write or crash when transcoding component model stringsRUSTSEC-2026-0092 Panic when transcoding misaligned component model UTF-16 stringsRUSTSEC-2026-0093 Heap OOB read in component model UTF-16 to latin1+utf16 string transcodingRUSTSEC-2026-0094 Improperly masked return value from `table.grow` with Winch compiler backendRUSTSEC-2025-0046 Host panic with `fd_renumber` WASIp1 functionRUSTSEC-2025-0118 Unsound API access to a WebAssembly shared linear memoryRUSTSEC-2026-0088 Data leakage between pooling allocator instancesRUSTSEC-2025-0057 fxhash - no longer maintainedRUSTSEC-2024-0436 paste - no longer maintainedRUSTSEC-2026-0173 proc-macro-error2 is unmaintainedRUSTSEC-2026-0206 `rustybuzz` is unmaintainedCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.