Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2021-23592 Deserialization of Untrusted Data in topthink/frameworkCVE-2021-36564 Deserialization of Untrusted Data in topthink/frameworkCVE-2022-47945 ThinkPHP Framework vulnerable to remote code executionCVE-2021-32708 Flysystem is an open source file storage library for PHP. The whitespa ...CVE-2024-34467 ThinkPHP Cross-Site Scripting VulnerabilityYour dependencies cross-checked against the OSV vulnerability database.
GHSA-9f46-5r25-5wfm Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystemGHSA-33gc-6cw9-w3g4 Deserialization of Untrusted Data in topthink/frameworkGHSA-3fpv-54ff-wqfj Deserialization of Untrusted Data in topthink/frameworkGHSA-g377-x8rg-c9mf Deserialization of Untrusted Data in topthink/frameworkGHSA-p4qr-vq2g-22wp ThinkPHP Framework vulnerable to remote code executionGHSA-qjjj-7g7h-54v3 ThinkPHP deserialization vulnerabilityGHSA-qrvj-274h-hfcg Deserialization of Untrusted Data in topthink/frameworkGHSA-969f-v7jv-pgj3 ThinkPHP Cross-Site Scripting VulnerabilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.