Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodiesCVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handlingCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2025-29927 nextjs: Authorization Bypass in Next.js MiddlewareCVE-2025-55182 next: React Server Components: Pre-authentication remote code execution via unsafe deserializationCVE-2025-29927 nextjs: Authorization Bypass in Next.js MiddlewareCVE-2025-55182 next: React Server Components: Pre-authentication remote code execution via unsafe deserializationCVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2026-59940 seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationCVE-2026-59940 seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationCVE-2026-59940 seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2024-56201 jinja2: Jinja has a sandbox breakout through malicious filenamesCVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format methodCVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format methodCVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputsCVE-2026-28684 python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link followingCVE-2024-53981 python-multipart: python-multipart has a DoS via deformation `multipart/form-data` boundaryCVE-2026-24486 python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerabilityCVE-2026-42561 python-multipart: python-multipart: Denial of Service via excessive multipart part headersCVE-2026-53539 python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodiesCVE-2026-40347 python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requestsCVE-2024-47874 starlette: Starlette Denial of service (DoS) via multipart/form-dataCVE-2026-48818 starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on WindowsCVE-2026-54283 starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-348 h11 accepts some malformed Chunked-Encoding bodiesGHSA-279x-mwfv-vcqv Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's hostGHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-593f-38f6-jp5m Inefficient Regular Expression Complexity in koaGHSA-9qr9-h5gf-34mp Next.js is vulnerable to RCE in React flight protocolGHSA-9qr9-h5gf-34mp Next.js is vulnerable to RCE in React flight protocolGHSA-f82v-jwr5-mffw Authorization Bypass in Next.js MiddlewareGHSA-9qr9-h5gf-34mp Next.js is vulnerable to RCE in React flight protocolGHSA-f82v-jwr5-mffw Authorization Bypass in Next.js MiddlewareGHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-mv8w-475r-vwqw seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationGHSA-mv8w-475r-vwqw seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationGHSA-mv8w-475r-vwqw seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationGHSA-w7jw-789q-3m8p shell-quote quote() does not escape newlines in object .op valuesGHSA-hffm-xvc3-vprc simple-git is vulnerable to Remote Code ExecutionGHSA-r275-fr43-pm7q simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCEGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-3qcw-2rhx-2726 Turbo: Unexpected local code execution during Yarn Berry detectionGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedGHSA-9crc-q9x8-hgqq Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listeningPYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1472 Jinja has a sandbox breakout through malicious filenamesPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.