Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 11 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 11 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
11 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
500 of 1903 files scanned (26%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 1903 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 11 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.1.12 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
2.0.2 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
5.0.6 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — HIGH
1.13.4 — GHSA-5375-pq7m-f5r2, GHSA-99f4-grh7-6pcq
@grpc/grpc-js: A malformed request can cause a server crash — HIGH
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash — HIGH
4.17.21 — GHSA-f23m-r3pf-42rh, GHSA-r5fr-rjxr-66jc, GHSA-xxjr-mmjv-4gpg
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — devDependency
lodash vulnerable to Code Injection via `_.template` imports key names — devDependency
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions — devDependency
10.0.3 — GHSA-23c5-xmqv-rm74, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions — devDependency
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern — devDependency
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments — devDependency
2.48.0 — GHSA-28xr-mwxg-3qc8, GHSA-3f95-r44v-8mrg, GHSA-9p95-fxvg-qgq2
Command injection in simple-git — devDependency
Command injection in simple-git — devDependency
simple-git vulnerable to Remote Code Execution when enabling the ext transport protocol — devDependency
4.1.6 — GHSA-g8mr-85jm-7xhm, GHSA-p63j-vcc4-9vmv
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE — devDependency
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate — devDependency
1.1.12 — GHSA-f886-m6hf-6m8v
brace-expansion: Zero-step sequence causes process hang and memory exhaustion — MODERATE
2.0.2 — GHSA-f886-m6hf-6m8v
brace-expansion: Zero-step sequence causes process hang and memory exhaustion — MODERATE
4.5.3 — GHSA-fj3w-jwp8-x2g3, GHSA-gh4j-gqv2-49f6
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder — LOW
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters — MODERATE
10.4.5 — GHSA-5j98-mcp5-4vw2
glob CLI: Command injection via -c/--cmd executes matches with shell:true — devDependency
11.0.3 — GHSA-5j98-mcp5-4vw2
glob CLI: Command injection via -c/--cmd executes matches with shell:true — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 1903 files (highest-priority subset) · date-fns/date-fns
Dependency manifests: 28 package roots found, 15 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)