Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodiesCVE-2025-68146 filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbitrary file corruption or truncationCVE-2026-22701 filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLockCVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputsCVE-2026-41066 lxml: python: lxml: Information disclosure via untrusted XML input leading to local file readCVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequencesCVE-2025-4565 python-protobuf: Unbounded recursion in Python ProtobufCVE-2026-0994 python: protobuf: Protobuf: Denial of Service due to recursion depth bypassCVE-2025-71176 pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handlingCVE-2026-28684 python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link followingCVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLsCVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creationCVE-2025-62727 starlette: Starlette DoS via Range header mergingCVE-2026-48818 starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on WindowsCVE-2026-54283 starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSCVE-2025-54121 starlette: Starlette denial-of-serviceCVE-2026-48710 starlette: Starlette: Security restriction bypass via malformed HTTP Host headerCVE-2026-48817 starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methodsCVE-2024-11392 transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution VulnerabilityCVE-2024-11393 transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityCVE-2024-11394 transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityCVE-2026-4372 HuggingFace transformers vulnerable to remote code executionCVE-2026-5241 python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingCVE-2024-12720 Transformers Regular Expression Denial of Service (ReDoS) vulnerabilityCVE-2025-1194 Transformers Regular Expression Denial of Service (ReDoS) vulnerabilityYour dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.