Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 9 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 9 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
9 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
83 of 111 files scanned (74%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 83 of 111 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 9 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
1.1.11 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
1.0.3 — GHSA-j383-35pm-c5h4, GHSA-m5pj-vjjf-4m3h, GHSA-rm36-94g8-835r
Path Traversal in Grunt — devDependency
Arbitrary Code Execution in grunt — devDependency
Race Condition in Grunt — devDependency
3.5.5 — GHSA-2pr6-76vf-7546, GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj
Denial of Service in js-yaml — devDependency
js-yaml: YAML merge-key chains can force quadratic CPU consumption — devDependency
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — devDependency
0.4.4 — GHSA-3v6h-hqm4-2rg6, GHSA-xcpc-8h2w-3j85
Arbitrary File Write in adm-zip — devDependency
adm-zip: Crafted ZIP file triggers 4GB memory allocation — devDependency
6.10.0 — GHSA-2g4f-4pwh-qvx6, GHSA-v88g-cgmw-v5xw
ajv has ReDoS when using `$data` option — devDependency
Prototype Pollution in Ajv — devDependency
1.4.0 — GHSA-73rr-hh4g-fpgx, GHSA-h6ch-v84p-w6p9
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch — devDependency
Regular Expression Denial of Service (ReDoS) — devDependency
4.16.4 — GHSA-qw6h-vgh9-j6wx, GHSA-rv95-896h-c2vc
express vulnerable to XSS via response.redirect() — LOW
Express.js Open Redirect in malformed URLs — MODERATE
2.1.4 — GHSA-fjxv-7rqg-78g4, GHSA-hmw2-7cc7-3qxx
form-data uses unsafe random function in form-data for choosing boundary — devDependency
form-data: CRLF injection in form-data via unescaped multipart field names and filenames — devDependency
2.16.3 — GHSA-c429-5p7v-vgjp, GHSA-jp4x-w63m-7wgm
hoek subject to prototype pollution via the clone function. — devDependency
Prototype Pollution in hoek — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 83 of 111 files · OWASP/NodeGoat
Dependency manifests: 1 package root found, 1 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)