Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 8 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 8 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
8 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
500 of 8541 files scanned (5%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 8541 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 8 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.2.1 — GHSA-5p2g-fcmc-qvqq, GHSA-w3rx-r6r6-pgpr
image-size: JXL and HEIF parsers allow denial of service through infinite loops — HIGH
image-size: ICNS parser allows denial of service through an infinite loop — HIGH
apps/admin-x-framework/src/test/msw-utils.ts:127
:127 — token:…ing', — non-production path
apps/admin-x-framework/test/unit/api/tinybird.test.tsx:57, :64, :74, :86, :87, :97, :104, :120, :135, :143, :151, :160
:57 — json: { tinybird: { token:…123' } }, — non-production path
:64 — expect(result.current.data).toEqual({ tinybird: { token:…123' } }); — non-production path
:74 — json: { tinybird: { token:…ken' } }, — non-production path
:86 — expect(result1.current.data).toEqual({ tinybird: { token:…ken' } }); — non-production path
:87 — expect(result2.current.data).toEqual({ tinybird: { token:…ken' } }); — non-production path
:97 — json: { tinybird: { token:…ken' } }, — non-production path
:104 — expect(result.current.data).toEqual({ tinybird: { token:…ken' } }); — non-production path
:120 — json: { tinybird: { token:…ken' } }, — non-production path
:135 — expect(result2.current.data).toEqual({ tinybird: { token:…ken' } }); — non-production path
:143 — json: { tinybird: { token:…ken' } }, — non-production path
:151 — expect(result.current.data).toEqual({ tinybird: { token:…ken' } }); — non-production path
:160 — json: { tinybird: { token:…ken' } }, — non-production path
apps/admin-x-framework/test/unit/hooks/use-active-visitors.test.ts:451
:451 — token:…ken', — non-production path
apps/admin-x-framework/test/unit/hooks/use-tinybird-token.test.tsx:50, :80, :164, :189, :249, :281
:50 — data: { tinybird: { token:…123' } }, — non-production path
:80 — data: { tinybird: { token:…ken' } }, — non-production path
:164 — data: { tinybird: { token:…ken' } }, — non-production path
:189 — data: { tinybird: { token:…ken' } }, — non-production path
:249 — data: { tinybird: { token:…ken' } }, — non-production path
:281 — data: { tinybird: { token:…ken' } }, — non-production path
4.12.18 — GHSA-2gcr-mfcq-wcc3, GHSA-3hrh-pfw6-9m5x, GHSA-54fx-42gc-7vw4
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths — MODERATE
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection — MODERATE
Hono: Algorithmic Complexity DoS in Language Middleware — MODERATE
8.5.1 — GHSA-hjrf-2m68-5959, GHSA-qwph-4952-7xr6
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC — MODERATE
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify() — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 8541 files (highest-priority subset) · TryGhost/Ghost
Dependency manifests: 57 package roots found, 13 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)