Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 1 high/critical dependency vulnerability. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 1 serious security bug in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
1 critical dependency vulnerability found. 11 more dimensions need Audit for the full picture.
380 of 394 files scanned (96%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 380 of 394 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 1 high or critical vulnerability in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.3.1 — GHSA-2328-f5f3-gj25, GHSA-554w-wpv2-vw27, GHSA-5gfm-wpxj-wjgq
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) — devDependency
node-forge has ASN.1 Unbounded Recursion — devDependency
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization — devDependency
8.0.0 — GHSA-35p6-xmwp-9g52, GHSA-38rv-x7px-6hhq, GHSA-4cwx-7wf7-3272
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse — devDependency
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass — devDependency
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives — devDependency
5.49.0 — GHSA-38r7-794h-5758, GHSA-4vvj-4cpr-p986, GHSA-8fgc-7cc6-rx7x
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence — devDependency
Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS — devDependency
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 380 of 394 files · fastify/fastify
Dependency manifests: 3 package roots found, 3 scanned.
[](https://nittim.com)