Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 7 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 7 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
7 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
500 of 666 files scanned (75%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 666 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 7 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.1.11 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
2.0.1 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
15.5.15 — GHSA-267c-6grr-h53f, GHSA-26hh-7cqf-hhc6, GHSA-36qx-fr4f-26g5
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes — HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up — HIGH
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n — HIGH
1.1.11 — GHSA-f886-m6hf-6m8v
brace-expansion: Zero-step sequence causes process hang and memory exhaustion — MODERATE
2.0.1 — GHSA-f886-m6hf-6m8v
brace-expansion: Zero-step sequence causes process hang and memory exhaustion — MODERATE
8.5.12 — GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — devDependency
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure — devDependency
7.3.2 — GHSA-fx2h-pf6j-xcff, GHSA-v6wh-96g9-6wx3
vite: `server.fs.deny` bypass on Windows alternate paths — devDependency
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 666 files (highest-priority subset) · colinhacks/zod
Dependency manifests: 8 package roots found, 5 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)