reports, already run
Report library
86 real nittim Free scans of public open-source code. Open one before you show us anything of yours.86 real nittim Free scans of public open-source code. Open one before you show us anything of your own.86 real nittim Free scans of public code. Open one before you show us yours.
What you're looking at
Every report below came from the deterministic Free scan: a secret scanner and a dependency check, both running on nittim's own servers, with no AI in the path at all. Two numbers travel with each one — how many files the scanners read, and how many they found — so you can see the reach of the report you're about to read.Every report below came from the free, rule-based scan: a check for passwords or keys left in the code, and a check for known security bugs in the ready-made packages the project uses — both running on nittim's own servers, with no AI involved at all. Two numbers travel with each report — how many files were checked, and how many problems turned up — so you can see how much of the project the report you're about to read actually covers.Every report below is a deterministic Free scan: a secret scanner and dependency check on nittim's own servers, no AI. Each carries two numbers — files read, findings — so you see the report's reach before opening it.
What you will not find here is a verdict. A Free scan reports hard evidence — a committed credential, a known-vulnerable dependency — or it reports that it turned up nothing verdict-bearing. Neither of those is a judgment about whether a codebase is safe to ship. That takes Audit, which reads the code and reasons about it. Where a Audit report exists for one of these repositories, the row links it too.What you will not find here is a final verdict. A Free scan reports hard evidence — a password left in the code, a package with a known security bug — or it reports that it found nothing of that kind. Neither of those is a judgment about whether the code is actually safe to ship. That takes Audit, which reads the code and reasons about it. Where an Audit report exists for one of these projects, the row links to it too.Free scan reports hard evidence — a committed credential, a known-vulnerable dependency — or nothing verdict-bearing. Neither is a judgment on whether the code is safe to ship. Audit reads the code and reasons about it — where a Audit report exists, the row links it too.
Reports here are ordinary scan pages, owned by a nittim account and public because the repositories are. Run the same scan yourself on any public repository and you get a page just like these — no sign-in, no card.Reports here are ordinary scan pages, owned by a nittim account and public because the projects themselves are public. Run the same scan yourself on any public project and you get a page just like these — no sign-in, no card.These are ordinary scan pages — owned by a nittim account, public because the repos are. Run the same scan on any public repo and get a page just like these — no sign-in, no card.
Large and complex
Popular libraries
Broken on purpose
RusDavies/security-defect-corpus
1 secretHard evidencecisco-foundation-ai/vulnerability-localization-benchmark
Nothing verdict-bearingOWASP/Vulnerable-Web-Application
Nothing verdict-bearingPinned to a known-vulnerable release
A scanner reads what a project depends on, not what the project is — so pinning lodash to the release before its own CVE does not make the dependency check flag lodash. Seven of these eight report nothing verdict-bearing for exactly that reason, and that is the point of the shelf: it shows you where the deterministic tier stops. Reading the code and recognising the flaw is what Audit is for.
expressjs/express4.19.1
4 critical deps10 advisoriesHard evidenceaxios/axiosv1.5.1
21 advisoriesNothing verdict-bearingjpadilla/pyjwt2.3.0
Nothing verdict-bearinglodash/lodash4.17.11
60 advisoriesNothing verdict-bearingminimistjs/minimistv1.2.5
Nothing verdict-bearingnpm/node-tarv6.1.10
35 advisoriesNothing verdict-bearingpsf/requestsv2.30.0
Nothing verdict-bearingyaml/pyyaml5.3.1
Nothing verdict-bearingWritten by an AI
Authorship here is each repository's own claim, quoted from its README — not a judgment this product made about the code. These are the closest public stand-ins for what nittim is built to audit.
kingsidharth/vocal-note-keeper-ai
8 critical deps37 advisoriesHard evidenceSathyamoorthy17/master-quiz-nexus
1 secret7 critical deps35 advisoriesHard evidencemaciej-trebacz/tower-of-time-game
3 advisoriesNothing verdict-bearingMountainsCalling-me/property-dashboard
17 advisoriesNothing verdict-bearingVery small
AhmedAdelFahim/express-xss-sanitizer
3 advisoriesNothing verdict-bearing