reports, already run

Report library

86 real nittim Free scans of public open-source code. Open one before you show us anything of yours.86 real nittim Free scans of public open-source code. Open one before you show us anything of your own.86 real nittim Free scans of public code. Open one before you show us yours.

What you're looking at

The same Free scan you can run on your own repo in a few seconds — already run, on code you know.

Every report below came from the deterministic Free scan: a secret scanner and a dependency check, both running on nittim's own servers, with no AI in the path at all. Two numbers travel with each one — how many files the scanners read, and how many they found — so you can see the reach of the report you're about to read.Every report below came from the free, rule-based scan: a check for passwords or keys left in the code, and a check for known security bugs in the ready-made packages the project uses — both running on nittim's own servers, with no AI involved at all. Two numbers travel with each report — how many files were checked, and how many problems turned up — so you can see how much of the project the report you're about to read actually covers.Every report below is a deterministic Free scan: a secret scanner and dependency check on nittim's own servers, no AI. Each carries two numbers — files read, findings — so you see the report's reach before opening it.

What you will not find here is a verdict. A Free scan reports hard evidence — a committed credential, a known-vulnerable dependency — or it reports that it turned up nothing verdict-bearing. Neither of those is a judgment about whether a codebase is safe to ship. That takes Audit, which reads the code and reasons about it. Where a Audit report exists for one of these repositories, the row links it too.What you will not find here is a final verdict. A Free scan reports hard evidence — a password left in the code, a package with a known security bug — or it reports that it found nothing of that kind. Neither of those is a judgment about whether the code is actually safe to ship. That takes Audit, which reads the code and reasons about it. Where an Audit report exists for one of these projects, the row links to it too.Free scan reports hard evidence — a committed credential, a known-vulnerable dependency — or nothing verdict-bearing. Neither is a judgment on whether the code is safe to ship. Audit reads the code and reasons about it — where a Audit report exists, the row links it too.

Reports here are ordinary scan pages, owned by a nittim account and public because the repositories are. Run the same scan yourself on any public repository and you get a page just like these — no sign-in, no card.Reports here are ordinary scan pages, owned by a nittim account and public because the projects themselves are public. Run the same scan yourself on any public project and you get a page just like these — no sign-in, no card.These are ordinary scan pages — owned by a nittim account, public because the repos are. Run the same scan on any public repo and get a page just like these — no sign-in, no card.

Large and complex

27 reports — Production codebases with years of history — CMSes, chat servers, analytics platforms.

mattermost/mattermost

19 critical deps29 advisoriesHard evidence

Team chat in Go and React, deployed inside regulated networks.

TypeScriptread 138 of 15,580 filesOpen report →

open-webui/open-webui

1 secret13 critical deps22 advisoriesHard evidence

A self-hosted chat interface for local and hosted models.

Pythonread 352 of 5,031 filesOpen report →Audit report →

calcom/cal.diy

13 critical deps28 advisoriesHard evidence

Scheduling infrastructure — the open answer to Calendly.

TypeScriptread 466 of 7,695 filesOpen report →

grafana/grafana

1 secret10 critical deps9 advisoriesHard evidence

Dashboards and observability — a Go backend under a big TypeScript frontend.

TypeScriptread 485 of 22,635 filesOpen report →

PostHog/posthog

10 critical deps41 advisoriesHard evidence

Product analytics, session replay and feature flags in one Django app.

Pythonread 72 of 45,289 filesOpen report →

medusajs/medusa

8 critical deps17 advisoriesHard evidence

A commerce backend: carts, orders, payments, plugins.

TypeScriptread 465 of 23,852 filesOpen report →

TryGhost/Ghost

8 critical deps7 advisoriesHard evidence

The publishing platform behind a large share of paid newsletters.

JavaScriptread 500 of 8,541 filesOpen report →

appwrite/appwrite

4 secrets13 advisoriesHard evidence

Backend-as-a-service: auth, storage, functions, databases.

TypeScriptread 500 of 3,118 filesOpen report →

twentyhq/twenty

3 critical deps1 advisoryHard evidence

A CRM written in TypeScript, aimed squarely at Salesforce.

TypeScriptread 448 of 28,694 filesOpen report →

home-assistant/core

2 critical deps1 advisoryHard evidence

Thousands of near-independent device integrations in one Python codebase.

Pythonread 500 of 27,128 filesOpen report →

n8n-io/n8n

1 secret1 critical dep9 advisoriesHard evidence

Workflow automation with hundreds of third-party integrations.

TypeScriptread 500 of 27,113 filesOpen report →

plausible/analytics

2 critical deps2 advisoriesHard evidence

Privacy-first web analytics in Elixir and Phoenix.

Elixirread 500 of 2,027 filesOpen report →

discourse/discourse

1 critical dep5 advisoriesHard evidence

The Rails forum software running much of the web's community discussion.

Rubyread 500 of 24,408 filesOpen report →

mastodon/mastodon

1 secretHard evidence

Federated microblogging — Rails, Sidekiq and a lot of ActivityPub.

Rubyread 500 of 9,972 filesOpen report →

directus/directus

6 advisoriesNothing verdict-bearing

Turns an existing SQL database into a headless CMS and API.

TypeScriptread 500 of 4,625 filesOpen report →

DSpace/DSpace

Nothing verdict-bearing

A Java repository platform running university archives worldwide.

Javaread 500 of 4,782 filesOpen report →Audit report →

formbricks/formbricks

Nothing verdict-bearing

Surveys and in-product research, self-hosted.

TypeScriptread 500 of 4,685 filesOpen report →

getsentry/sentry

3 advisoriesNothing verdict-bearing

Error tracking itself: a Django backend and a large React frontend in one repo.

Pythonread 498 of 20,512 filesOpen report →

go-gitea/gitea

1 advisoryNothing verdict-bearing

A self-hosted Git service in Go — issues, CI and packages.

Goread 500 of 6,229 filesOpen report →

metabase/metabase

35 advisoriesNothing verdict-bearing

Business intelligence in Clojure — dashboards over your own database.

Clojureread 484 of 21,435 filesOpen report →

nextcloud/server

Nothing verdict-bearing

Self-hosted file sync and collaboration, in PHP.

PHPread 484 of 12,791 filesOpen report →

odoo/odoo

Nothing verdict-bearing

An ERP suite large enough to carry its own web framework.

Pythonread 255 of 48,066 filesOpen report →Audit report →

postgres/postgres

Nothing verdict-bearing

The database itself. Millions of lines of C, and three decades of review.

Cread 500 of 7,699 filesOpen report →Audit report →

saleor/saleor

16 advisoriesNothing verdict-bearing

A GraphQL commerce API in Django, running real storefronts.

Pythonread 500 of 4,671 filesOpen report →

simplcommerce/SimplCommerce

Nothing verdict-bearing

An ASP.NET Core storefront — the .NET end of the scale.

C#read 257 of 1,992 filesOpen report →Audit report →

strapi/strapi

2 advisoriesNothing verdict-bearing

A headless CMS with an admin app, a plugin system and a plugin API.

TypeScriptread 500 of 6,535 filesOpen report →

supabase/supabase

11 advisoriesNothing verdict-bearing

The Postgres platform, as a monorepo of studio, docs and services.

TypeScriptread 71 of 16,949 filesOpen report →Audit report →

Popular libraries

20 reports — The mature, heavily-reviewed packages the rest of the ecosystem depends on.

date-fns/date-fns

11 critical deps25 advisoriesHard evidence

Date utilities with no runtime dependencies.

TypeScriptread 500 of 1,903 filesOpen report →

colinhacks/zod

7 critical deps10 advisoriesHard evidence

TypeScript-first schema validation, no runtime dependencies.

TypeScriptread 500 of 666 filesOpen report →Audit report →

fastify/fastify

1 critical dep11 advisoriesHard evidence

A low-overhead Node framework with schema-driven validation.

JavaScriptread 380 of 394 filesOpen report →Audit report →

ai/nanoid

Nothing verdict-bearing

A 118-byte ID generator that takes its randomness seriously.

JavaScriptread 41 of 49 filesOpen report →

BurntSushi/ripgrep

Nothing verdict-bearing

A search tool written for speed and reviewed for correctness.

Rustread 160 of 236 filesOpen report →

expressjs/express

1 advisoryNothing verdict-bearing

The minimalist Node framework, at its maintained default branch.

JavaScriptread 173 of 213 filesOpen report →Audit report →

gin-gonic/gin

1 advisoryNothing verdict-bearing

A fast HTTP framework in Go, in production nearly everywhere.

Goread 124 of 130 filesOpen report →

jpadilla/pyjwt

Nothing verdict-bearing

JSON Web Tokens in Python — small, security-sensitive, widely deployed.

Pythonread 65 of 92 filesOpen report →Audit report →

lodash/lodash

60 advisoriesNothing verdict-bearing

The utility library much of npm still depends on.

JavaScriptread 48 of 160 filesOpen report →

nodeca/js-yaml

12 advisoriesNothing verdict-bearing

The YAML parser most JavaScript tooling loads.

TypeScriptread 121 of 128 filesOpen report →

pallets/click

Nothing verdict-bearing

Composable command-line interfaces for Python.

Pythonread 147 of 166 filesOpen report →

pallets/flask

9 advisoriesNothing verdict-bearing

The Python micro-framework, reviewed for well over a decade.

Pythonread 142 of 236 filesOpen report →

pallets/jinja

Nothing verdict-bearing

The templating engine under Flask and Ansible.

Pythonread 84 of 107 filesOpen report →

panva/jose

Nothing verdict-bearing

JWT, JWS, JWE and JWK for Node, browsers and edge runtimes.

TypeScriptread 338 of 343 filesOpen report →

postcss/postcss

Nothing verdict-bearing

The CSS transformer under Tailwind and Autoprefixer.

TypeScriptread 110 of 115 filesOpen report →

psf/requests

Nothing verdict-bearing

The HTTP library most Python code reaches for first.

Pythonread 77 of 128 filesOpen report →

pyca/cryptography

2 advisoriesNothing verdict-bearing

Python's cryptographic primitives, with a Rust core.

Pythonread 302 of 3,046 filesOpen report →

serde-rs/serde

Nothing verdict-bearing

Rust's serialization framework, depended on by most of crates.io.

Rustread 227 of 347 filesOpen report →

spf13/cobra

Nothing verdict-bearing

The CLI framework under kubectl, Hugo and the Docker CLI.

Goread 63 of 66 filesOpen report →

tj/commander.js

3 advisoriesNothing verdict-bearing

Command-line argument parsing, no runtime dependencies.

JavaScriptread 197 of 216 filesOpen report →

Broken on purpose

15 reports — Training targets built to be vulnerable — where the scanners should have plenty to say.

snoopysecurity/dvws-node

30 critical deps19 advisoriesHard evidence

Damn Vulnerable Web Services — broken APIs, by design.

JavaScriptread 60 of 70 filesOpen report →

juice-shop/juice-shop

1 secret15 critical deps11 advisoriesHard evidence

OWASP's deliberately broken shop — the canonical training target.

TypeScriptread 387 of 1,300 filesOpen report →Audit report →

appsecco/dvna

14 critical deps10 advisoriesHard evidence

Damn Vulnerable NodeJS Application — the Top 10, on purpose.

SCSSread 41 of 151 filesOpen report →

OWASP/NodeGoat

9 critical deps36 advisoriesHard evidence

OWASP's Node app for learning the Top 10 by exploiting it.

HTMLread 83 of 111 filesOpen report →

anxolerd/dvpwa

4 critical deps8 advisoriesHard evidence

Damn Vulnerable Python Web App — SQLi, XSS and CSRF by design.

Pythonread 33 of 58 filesOpen report →

payatu/Tiredful-API

2 critical deps4 advisoriesHard evidence

A REST API broken on purpose, for API-security practice.

Pythonread 84 of 130 filesOpen report →

NetSPI/django.nV

1 critical dep2 advisoriesHard evidence

A Django app with planted flaws, used in security training.

JavaScriptread 138 of 190 filesOpen report →

OWASP/railsgoat

1 secretHard evidence

A Rails app built to fail the OWASP Top 10.

HTMLread 168 of 275 filesOpen report →

A corpus of planted security defects, written to test detectors.

Pythonread 449 of 450 filesOpen report →Audit report →

A research corpus of labelled, localized vulnerabilities.

Pythonread 29 of 35 filesOpen report →Audit report →

digininja/DVWA

Nothing verdict-bearing

The PHP app security courses have taught with for over a decade.

PHPread 223 of 252 filesOpen report →

OWASP-Benchmark/BenchmarkJava

4 advisoriesNothing verdict-bearing

OWASP's scanner test suite — thousands of labelled Java cases.

Javaread 29 of 5,725 filesOpen report →Audit report →

OWASP/Vulnerable-Web-Application

Nothing verdict-bearing

An OWASP PHP target carrying planted vulnerabilities.

PHPread 38 of 45 filesOpen report →

SasanLabs/VulnerableApp

Nothing verdict-bearing

A Java target built for benchmarking security scanners.

Javaread 330 of 461 filesOpen report →Audit report →

stamparm/DSVW

Nothing verdict-bearing

Damn Small Vulnerable Web — dozens of classic flaws in one file.

Pythonread 11 of 12 filesOpen report →

Pinned to a known-vulnerable release

8 reports — Each library at the exact commit before its published CVE was fixed.

A scanner reads what a project depends on, not what the project is — so pinning lodash to the release before its own CVE does not make the dependency check flag lodash. Seven of these eight report nothing verdict-bearing for exactly that reason, and that is the point of the shelf: it shows you where the deterministic tier stops. Reading the code and recognising the flaw is what Audit is for.

expressjs/express4.19.1

4 critical deps10 advisoriesHard evidence

Express one release before the 4.19.2 fix for CVE-2024-29041 — a malformed URL survived into the Location header.

JavaScriptread 190 of 231 filesOpen report →

axios/axiosv1.5.1

21 advisoriesNothing verdict-bearing

Axios before 1.6.0, where the XSRF token rode along to any host the client talked to (CVE-2023-45857).

JavaScriptread 193 of 224 filesOpen report →

jpadilla/pyjwt2.3.0

Nothing verdict-bearing

PyJWT before 2.4.0, where an ssh-formatted ed25519 public key could be used as an HMAC secret (CVE-2022-29217).

Pythonread 52 of 76 filesOpen report →

lodash/lodash4.17.11

60 advisoriesNothing verdict-bearing

Lodash before 4.17.12 — defaultsDeep could be walked into Object.prototype (CVE-2019-10744).

JavaScriptread 36 of 148 filesOpen report →

minimistjs/minimistv1.2.5

Nothing verdict-bearing

minimist before 1.2.6, whose argv parser wrote straight into __proto__ (CVE-2021-44906).

JavaScriptread 19 of 21 filesOpen report →

npm/node-tarv6.1.10

35 advisoriesNothing verdict-bearing

node-tar before 6.1.11 — a crafted archive could poison the directory cache and write outside the root (CVE-2021-32803).

JavaScriptread 202 of 237 filesOpen report →

psf/requestsv2.30.0

Nothing verdict-bearing

Requests before 2.31.0 — proxy credentials survived a redirect (CVE-2023-32681).

Pythonread 62 of 100 filesOpen report →

yaml/pyyaml5.3.1

Nothing verdict-bearing

PyYAML before 5.4, where FullLoader could still be talked into building arbitrary objects (CVE-2020-14343).

Pythonread 88 of 669 filesOpen report →

Written by an AI

9 reports — Apps whose own README credits Lovable, v0, Bolt or Claude Code for the code.

Authorship here is each repository's own claim, quoted from its README — not a judgment this product made about the code. These are the closest public stand-ins for what nittim is built to audit.

R44VC0RP/agenda.dev

30 critical deps24 advisoriesHard evidence

A real-time todo app; the README credits v0.dev.

TypeScriptread 166 of 186 filesOpen report →Audit report →

0-x-joseph/freelanceros

17 critical deps18 advisoriesHard evidence

A freelance management platform wearing a "Built with Bolt.new" badge.

TypeScriptread 140 of 149 filesOpen report →

kingsidharth/vocal-note-keeper-ai

8 critical deps37 advisoriesHard evidence

Browser-local voice notes, built and hosted on Lovable.

TypeScriptread 102 of 107 filesOpen report →

Sathyamoorthy17/master-quiz-nexus

1 secret7 critical deps35 advisoriesHard evidence

A quiz builder whose README is still Lovable's default.

TypeScriptread 82 of 87 filesOpen report →

sandydargoport/prism

1 secret6 critical deps3 advisoriesHard evidence

A self-hosted family dashboard, README: "built entirely with Claude Code".

TypeScriptread 500 of 1,159 filesOpen report →

shayan-shojaei/open-tutor

6 critical deps11 advisoriesHard evidence

A self-hosted learning environment, "built entirely with Claude Code".

TypeScriptread 126 of 143 filesOpen report →

aggwrk/nihongo-blocks

1 secret3 critical deps37 advisoriesHard evidence

A Japanese flashcard app. The README opens "Welcome to your Lovable project".

TypeScriptread 116 of 121 filesOpen report →Audit report →

maciej-trebacz/tower-of-time-game

3 advisoriesNothing verdict-bearing

A game-jam tower defense the author calls a vibe-coding proof of concept.

TypeScriptread 56 of 106 filesOpen report →

MountainsCalling-me/property-dashboard

17 advisoriesNothing verdict-bearing

A property search CRM on Cloudflare Workers, built with Claude Code.

JavaScriptread 40 of 43 filesOpen report →

Very small

7 reports — A handful of files each — the far end of the scale, and a fast read.

AhmedAdelFahim/express-xss-sanitizer

3 advisoriesNothing verdict-bearing

One Express middleware, doing one thing to request input.

JavaScriptread 7 of 10 filesOpen report →Audit report →

debug-js/debug

2 advisoriesNothing verdict-bearing

The debugging utility almost every Node package pulls in.

JavaScriptread 11 of 13 filesOpen report →Audit report →

expressjs/cors

Nothing verdict-bearing

CORS middleware for Express — small, and everywhere.

JavaScriptread 16 of 17 filesOpen report →

i-voted-for-trump/is-odd

Nothing verdict-bearing

Nine files. The internet's favourite argument about small packages.

JavaScriptread 9 of 12 filesOpen report →

left-pad/left-pad

Nothing verdict-bearing

The eleven lines that briefly broke npm in 2016.

JavaScriptread 10 of 11 filesOpen report →

sindresorhus/p-limit

Nothing verdict-bearing

Concurrency limiting in a few dozen lines.

JavaScriptread 13 of 16 filesOpen report →

sindresorhus/slugify

Nothing verdict-bearing

String to URL slug. One job.

JavaScriptread 10 of 13 filesOpen report →