Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 6 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 6 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
6 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
126 of 143 files scanned (88%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 126 of 143 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 6 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
3.3.12 — GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8
nanoid: non-secure generators can loop indefinitely with negative size — HIGH
nanoid: custom generators can loop indefinitely when size is zero — HIGH
8.4.31 — GHSA-6g55-p6wh-862q, GHSA-fxqj-rqcc-2cmp, GHSA-qx2v-qp2m-jg93
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments — devDependency
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — devDependency
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output — devDependency
8.5.15 — GHSA-fxqj-rqcc-2cmp
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — MODERATE
0.21.5 — GHSA-67mh-4wv8-2f99
esbuild enables any website to send any requests to the development server and read the response — MODERATE
0.28.0 — GHSA-g7r4-m6w7-qqqr
esbuild allows arbitrary file read when running the development server on Windows — LOW
14.2.35 — GHSA-3g8h-86w9-wvmq, GHSA-3x4c-7xq6-9pq8
Next.js's Middleware / Proxy redirects can be cache-poisoned — LOW
Next.js: Unbounded next/image disk cache growth can exhaust storage — MODERATE
5.4.21 — GHSA-4w7w-66w2-5vf9, GHSA-v6wh-96g9-6wx3
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling — MODERATE
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 126 of 143 files · shayan-shojaei/open-tutor
Dependency manifests: 3 package roots found, 3 scanned; 2 Go manifests read.
[](https://nittim.com)