a public repository, read by nittim

Is AdguardTeam/AdGuardHome production ready?

What nittim read in this repository, and what it found. Public repository, public reading — sourced from its own code and dependency manifests, nothing else.

Network-wide ads & trackers blocking DNS server

TypeScript · 37.3k stars · last push October 8, 2026

AdguardTeam/AdGuardHome is a network-wide DNS server written in TypeScript that blocks advertisements and trackers. The repository provides a centralized solution for filtering unwanted content across all devices on a network by intercepting and managing DNS queries.

Nittim scanned 1663 files in AdguardTeam/AdGuardHome and found evidence of security concerns. The scan detected 1 committed credential on a production path and 6 vulnerable runtime dependencies. Two packages contained multiple known vulnerabilities: js-yaml with GHSA-2883-xcg3-v3hh, GHSA-52cp-r559-cp3m, and GHSA-5p4m-2wfm-xmqj, and nanoid with GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8, and GHSA-xwg4-73v4-xw9w.

Developers should update the vulnerable dependencies to versions that resolve these advisories. After making those changes, rescan the repository to confirm the issues are resolved. Running a full audit will provide detailed remediation guidance for each vulnerability and help prioritize fixes by severity.

Written from nittim's own scan on October 11, 2026; rescanned when the repository changes.

No verdict. The rule-based check reports hard evidence, or reports that it found none. Neither is a judgment on whether this code is safe to ship.

What was read — rule-based scan

Rule-based checks run on nittim's servers — a secret scanner and a dependency check, no model in the path. The code reached those two and stopped there.

Read 1663 of 1663 eligible files. Commit 8dedd32. 2026-10-11.

What the scanners found

Committed secrets on production paths
1
Vulnerable runtime dependencies
6

js-yaml (GHSA-2883-xcg3-v3hh, GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj), nanoid (GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8, GHSA-xwg4-73v4-xw9w)

Run it yourself

Scan any public repository in seconds — no sign-in, no card. Audit it to have a model read the code. Loop the report into your assistant to get the fixes applied and re-checked.

Scan your own repo

Questions

What did nittim read in AdguardTeam/AdGuardHome?
nittim read 1663 of 1663 eligible files in AdguardTeam/AdGuardHome. The reading ran on October 11, 2026. It was taken at commit 8dedd32.
Did nittim find committed secrets or vulnerable dependencies in AdguardTeam/AdGuardHome?
The rule-based scan found 1 committed secret and 6 vulnerable dependencies in AdguardTeam/AdGuardHome. Affected: js-yaml (GHSA-2883-xcg3-v3hh, GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj), nanoid (GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8, GHSA-xwg4-73v4-xw9w).
Is AdguardTeam/AdGuardHome production ready?
A free scan is not a verdict. A full audit gives one.

More like this

More TypeScript repositories →

Add the badge to your README
README badge
nittim verdict badge for AdguardTeam/AdGuardHome[![nittim](https://nittim.com/api/badge/AdguardTeam/AdGuardHome)](https://nittim.com/library/AdguardTeam/AdGuardHome)