Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code ExecutionCVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code ExecutionGHSA-xgfm-fjx6-62mj readthedocs-sphinx-search vulnerable to cross-site scripting when including search results from malicious projectsCVE-2021-3828 nltk is vulnerable to Inefficient Regular Expression ComplexityCVE-2021-3842 nltk is vulnerable to Inefficient Regular Expression ComplexityCVE-2021-43854 NLTK (Natural Language Toolkit) is a suite of open source Python modul ...CVE-2024-39705 NLTK through 3.8.1 allows remote code execution if untrusted packages ...CVE-2025-71408 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...CVE-2026-0846 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` functionCVE-2026-12061 Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexCVE-2026-12072 Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)CVE-2026-12074 Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)CVE-2026-12075 Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE modeCVE-2026-33231 nltk: NLTK: Denial of Service via unauthenticated remote shutdownCVE-2026-54293 nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`CVE-2026-33230 nltk: NLTK: Script execution via reflected cross-site scripting in WordNet BrowserCVE-2024-39705 NLTK through 3.8.1 allows remote code execution if untrusted packages ...CVE-2025-71408 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...CVE-2026-0846 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` functionCVE-2026-12061 Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexCVE-2026-12072 Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)CVE-2026-12074 Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)CVE-2026-12075 Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE modeCVE-2026-33231 nltk: NLTK: Denial of Service via unauthenticated remote shutdownCVE-2026-54293 nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`Your dependencies cross-checked against the OSV vulnerability database.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.