Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 14 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 14 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
14 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
41 of 151 files scanned (27%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 41 of 151 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 14 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
0.19.1 — GHSA-6433-x5p4-8jc7, GHSA-773h-w45w-f2f9, GHSA-jv72-59wq-8rxm
libxmljs vulnerable to type confusion when parsing specially crafted XML — CRITICAL
Denial of service vulnerability exists in libxmljs — HIGH
libxmljs has segmentation fault, potentially leading to a denial-of-service (DoS) — HIGH
3.10.1 — GHSA-pv8x-p9hq-j328, GHSA-vx5c-87qx-cv6c, GHSA-x2fc-mxcx-w4mf
Arbitrary Code Execution in mathjs — CRITICAL
Arbitrary Code Execution in mathjs — CRITICAL
Prototype Pollution in mathjs — HIGH
0.4.0 — GHSA-9wcg-jrwf-8gg7, GHSA-w4m6-x6c2-j5c9
Prototype Pollution in express-fileupload — CRITICAL
Express-FileUpload Arbitrary File Overwrite — HIGH
1.4.2 — GHSA-4rch-2fh8-94vw, GHSA-fpw7-j2hg-69v5
MySQL2 for Node Arbitrary Code Injection — CRITICAL
mysql2 Remote Code Execution (RCE) via the readCodeFor function — CRITICAL
4.16.2 — GHSA-qw6h-vgh9-j6wx, GHSA-rv95-896h-c2vc
express vulnerable to XSS via response.redirect() — LOW
Express.js Open Redirect in malformed URLs — MODERATE
4.13.10 — GHSA-8c25-f3mj-v6h8, GHSA-fw4p-36j9-rrj3
Sequelize information disclosure vulnerability — MODERATE
Denial of Service in sequelize — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 41 of 151 files · appsecco/dvna
Dependency manifests: 1 package root found, 1 scanned.
[](https://nittim.com)