Loading report…
← nittim
The secret and dependency scanners surfaced nothing verdict-bearing in what they scanned. This is not a clean bill of health. These two scanners cover a sliver of production-readiness — the 14 dimensions that actually decide whether you ship are unaudited below. Run Audit for the verdict.
The checks for leaked passwords and known package bugs found nothing to flag. This does not mean your code is safe. These two checks cover only a small slice of what matters — the 14 areas that actually decide whether your code is ready to ship are not checked yet. Run Audit for the full verdict.
No deterministic issues found — not a clean bill of health. 14 dimensions remain unaudited. Run Audit for the verdict.
500 of 4671 files scanned (10%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 4671 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. Neither found anything. That is not a clean bill of health. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
saleor/graphql/account/tests/mutations/authentication/test_password_change.py:23, :85, :105, :127
:23 — new_passwo…ion" — non-production path
:85 — new_passwo…ion" — non-production path
:105 — new_passwo…ion" — non-production path
:127 — new_passwo…ion" — non-production path
saleor/graphql/account/tests/mutations/authentication/test_set_password.py:50, :84, :89, :145, :189
:50 — passwo…ion" — non-production path
:84 — passwo…ord", — non-production path
:89 — passwo…ion" — non-production path
:145 — new_passwo…ord" — non-production path
:189 — passwo…ord" — non-production path
saleor/payment/gateways/stripe/tests/test_plugin_deprecated.py:24
:24 — client…ret" — non-production path
saleor/payment/gateways/stripe/tests/test_plugin.py:167, :225, :284, :348, :424, :517, :594, :691, :788, :890, :995, :1063, :1114
:167 — client…ret" — non-production path
:225 — client…ret" — non-production path
:284 — client…ret" — non-production path
:348 — client…ret" — non-production path
:424 — client…ret" — non-production path
:517 — client…ret" — non-production path
:594 — client…ret" — non-production path
:691 — client…ret" — non-production path
:788 — client…ret" — non-production path
:890 — client…ret" — non-production path
:995 — client…ret" — non-production path
:1063 — client…ret" — non-production path
:1114 — client…ret" — non-production path
5.0.5 — GHSA-5rq4-664w-9x2c, GHSA-6v7q-wjvx-w8wg, GHSA-rp42-5vxx-qpwr
Basic FTP has Path Traversal Vulnerability in its downloadToDir() method — devDependency
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands — devDependency
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() — devDependency
10.2.0 — GHSA-22jq-vg5j-6vgg, GHSA-4xrf-jv44-h6hh, GHSA-mwp4-54f8-5fhr
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — devDependency
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — devDependency
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — devDependency
4.17.21 — GHSA-f23m-r3pf-42rh, GHSA-r5fr-rjxr-66jc, GHSA-xxjr-mmjv-4gpg
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — devDependency
lodash vulnerable to Code Injection via `_.template` imports key names — devDependency
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions — devDependency
7.14.0 — GHSA-2mjp-6q6p-2qxm, GHSA-35p6-xmwp-9g52, GHSA-4992-7rv2-5pvq
Undici has an HTTP Request/Response Smuggling issue — devDependency
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse — devDependency
Undici has CRLF Injection in undici via `upgrade` option — devDependency
4.2.0 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj
js-yaml: YAML merge-key chains can force quadratic CPU consumption — devDependency
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — devDependency
2.3.1 — GHSA-3v7f-55p6-f55p, GHSA-c2c7-rcm5-vvqj
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching — devDependency
Picomatch has a ReDoS vulnerability via extglob quantifiers — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 4671 files (highest-priority subset) · saleor/saleor
Dependency manifests: 1 package root found, 1 scanned; 1 Python manifest read.
[](https://nittim.com)