Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 1 committed production secret and 15 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 1 password or key found in code that ships to production and 15 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
1 committed secret and 15 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
387 of 1300 files scanned (29%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 387 of 1300 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 1 committed credential on production paths and 15 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
1.4.5-lts.1 — GHSA-44fp-w29j-9vj5, GHSA-4pg4-qvpc-4q3h, GHSA-5528-5vmv-3xc2
Multer vulnerable to Denial of Service via memory leaks from unclosed streams — HIGH
Multer vulnerable to Denial of Service from maliciously crafted requests — HIGH
Multer Vulnerable to Denial of Service via Uncontrolled Recursion — HIGH
3.14.0 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj
js-yaml: YAML merge-key chains can force quadratic CPU consumption — HIGH
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — HIGH
0.4.0 — GHSA-8cf7-32gw-wr33, GHSA-c7hr-j4mj-j2w6
jsonwebtoken unrestricted key type could lead to legacy keys usage — HIGH
Verification Bypass in jsonwebtoken — CRITICAL
6.37.3 — GHSA-6457-6jrx-69cr, GHSA-v8fg-2rw7-q452
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type — HIGH
Sequelize: SQL Injection (Oracle DB) — CRITICAL
frontend/src/app/oauth/oauth.component.spec.ts:91, :98
:91 — expect(userService.save).toHaveBeenCalledWith({ email: 'test@test.com', passwo…A==', passwordRepeat: 'bW9jLnRzZXRAdHNldA==' }) — non-production path
:98 — expect(userService.login).toHaveBeenCalledWith({ email: 'test@test.com', passwo…A==', oauth: true }) — non-production path
frontend/src/app/Services/two-factor-auth-service.spec.ts:68
:68 — expect(req.request.body).toEqual({ password: 's3cr3t!', initialToken:…ken', setupToken: 'setupToken' }) — non-production path
frontend/src/app/two-factor-auth/two-factor-auth.component.spec.ts:243
:243 — twoFactorAuthService.status.mockReturnValue(of({ setup: false, email: 'e', secret…ret', setupToken: 't' })) — non-production path
test/api/2fa.test.ts:42, :66, :85, :104, :123, :141, :142, :156, :182, :214, :240, :257, :266, :291, :292, :317, :352, :379, :412
:42 — const totpToken = generateSync({ secret…3KH' }) — non-production path
:66 — const totpToken = generateSync({ secret…X4H' }) — non-production path
:85 — const totpToken = generateSync({ secret…3KH' }) — non-production path
:104 — const totpToken = generateSync({ secret…3KH' }) — non-production path
:123 — const totpToken = generateSync({ secret…3KH' }) — non-production path
:141 — passwo…EN!', — non-production path
:142 — totpSecret…3KH' — non-production path
:156 — passwo…6lB' — non-production path
:182 — const secret…ML7' — non-production path
:214 — const secret…ML7' — non-production path
:240 — const secret…ML7' — non-production path
:257 — initialToken: generateSync({ secret…QOJ' }) — non-production path
:266 — const secret…ML7' — non-production path
:291 — const passwo…EN!' — non-production path
:292 — const totpSecret…3KH' — non-production path
:317 — const secret…ML7' — non-production path
:352 — const totpSecret…ML7' — non-production path
:379 — const totpSecret…ML7' — non-production path
:412 — totpSecret…ML7' — non-production path
test/api/basket.test.ts:114, :170
:114 — passwo…mI=' — non-production path
:170 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
test/api/chat.test.ts:261
:261 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
test/api/data-export.test.ts:53, :73, :90, :110
:53 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:73 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:90 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:110 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
test/api/delivery.test.ts:54, :115
:54 — passwo…bJb' — non-production path
:115 — passwo…bJb' — non-production path
test/api/deluxe.test.ts:25, :40, :85, :128, :165
:25 — passwo…or!' — non-production path
:40 — passwo…bJb' — non-production path
:85 — passwo…or!' — non-production path
:128 — passwo…...' — non-production path
:165 — passwo…bJb' — non-production path
test/api/erasure-request.test.ts:36, :55, :68, :82, :94, :106
:36 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:55 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:68 — .send({ email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:82 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:94 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
:106 — const { token } = await login(app, { email: 'bjoern.kimminich@gmail.com', passwo…mI=' }) — non-production path
test/api/feedback.test.ts:117, :143
:117 — passwo…mI=' — non-production path
:143 — passwo…mI=' — non-production path
test/api/login.test.ts:90, :118, :132, :147, :245, :267
:90 — passwo…F$P' — non-production path
:118 — passwo…...' — non-production path
:132 — passwo…EN!' — non-production path
:147 — passwo…mI=' — non-production path
:245 — passwo…mI=' — non-production path
:267 — passwo…mI=' — non-production path
test/api/password.test.ts:95
:95 — passwo…or!' — non-production path
test/api/product-review.test.ts:101, :115
:101 — passwo…mI=' — non-production path
:115 — passwo…mI=' — non-production path
test/api/user-profile.test.ts:58
:58 — const { token } = await login(app, { email: 'ciso@juice-sh.op', passwo…bJb' }) — non-production path
test/api/user.test.ts:189, :240, :289, :304, :318
:189 — passwo…ter' — non-production path
:240 — passwo…mI=' — non-production path
:289 — passwo…mI=' — non-production path
:304 — passwo…mI=' — non-production path
:318 — passwo…mI=' — non-production path
test/cypress/e2e/changePassword.spec.ts:6, :25, :31
:6 — passwo…nce' — non-production path
:25 — passwo…or!' — non-production path
:31 — cy.login({ email: 'bender', passwo…sic' }) — non-production path
frontend/src/app/last-login-ip/last-login-ip.component.spec.ts:72, :78
:72 — localStorage.setItem('token', 'eyJhbG…t3bg') — non-production path
:78 — localStorage.setItem('token', 'eyJhbG…enLw') — non-production path
test/api/user.test.ts:280
:280 — .set({ Authorization: 'eyJhbG…pC8g' }) — non-production path
4.17.21 — GHSA-f23m-r3pf-42rh, GHSA-xxjr-mmjv-4gpg
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — MODERATE
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions — MODERATE
1.4.2 — GHSA-3j7m-hmh3-9jmp, GHSA-mjxr-4v3x-q3m4
Cross-Site Scripting in sanitize-html — MODERATE
Improper Input Validation in sanitize-html — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 387 of 1300 files (highest-priority subset) · juice-shop/juice-shop
Dependency manifests: 2 package roots found, 2 scanned.
[](https://nittim.com)