Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 4 committed production secrets. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 4 password or key found in code that ships to productions. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
4 committed secrets found. 11 more dimensions need Audit for the full picture.
500 of 3118 files scanned (16%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 3118 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 4 committed credentials on production paths and 0 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
src/Appwrite/Platform/Modules/Project/Http/Project/OAuth2/Apple/Update.php:99, :135
:99 — 'example' => '-----B…----MIGTAg...jy2Xbna-----END PRIVATE KEY-----',
:135 — ->param('p8File', null, new Nullable(new Text(4096, 0)), 'Contents of the Apple OAuth2 app .p8 private key file. The secret key wrapped by the PEM markers is 20
src/Appwrite/Utopia/Response/Model/OAuth2Apple.php:80
:80 — 'example' => '-----B…----MIGTAg...jy2Xbna-----END PRIVATE KEY-----',
tests/e2e/Services/Project/AuthMethodsIntegrationTest.php:66
:66 — $passwo…234'; — non-production path
tests/e2e/Services/Project/PoliciesPasswordHistoryIntegrationTest.php:37, :38, :39, :40, :127
:37 — $firstPasswo…ord'; — non-production path
:38 — $secondPasswo…ord'; — non-production path
:39 — $thirdPasswo…ord'; — non-production path
:40 — $fourthPasswo…ord'; — non-production path
:127 — $fifthPasswo…ord'; — non-production path
tests/e2e/Services/Project/PoliciesSessionAlertIntegrationTest.php:22
:22 — $passwo…234'; — non-production path
tests/e2e/Services/Project/PoliciesSessionDurationIntegrationTest.php:49
:49 — $passwo…234'; — non-production path
tests/e2e/Services/Project/PoliciesSessionInvalidationIntegrationTest.php:62, :89, :104
:62 — $firstPasswo…ord'; — non-production path
:89 — $secondPasswo…ord'; — non-production path
:104 — $thirdPasswo…ord'; — non-production path
tests/e2e/Services/Project/PoliciesSessionLimitIntegrationTest.php:36
:36 — $passwo…234'; — non-production path
tests/e2e/Services/ProjectWebhooks/WebhooksCustomClientTest.php:853
:853 — $passwo…rd2'; — non-production path
tests/e2e/Services/Webhooks/WebhooksBase.php:763, :807
:763 — $newSecret…ion'; — non-production path
:807 — $customSecret…key'; — non-production path
tests/unit/Auth/OAuth2/PKCETest.php:18
:18 — private const APP_SECRET…ret'; — non-production path
tests/unit/Utopia/Messaging/Adapter/WebhookTest.php:48
:48 — $secret…ret'; — non-production path
6.4.4 — GHSA-2pvr-wf23-7pc7, GHSA-4g3v-8h47-v7g6, GHSA-7pw4-f3q4-r2p2
Astro: Host header SSRF in prerendered error page fetch — devDependency
Astro: Reflected XSS via unescaped View Transition animation properties — devDependency
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands — devDependency
4.2.0 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj
js-yaml: YAML merge-key chains can force quadratic CPU consumption — devDependency
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — devDependency
3.3.12 — GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8
nanoid: non-secure generators can loop indefinitely with negative size — devDependency
nanoid: custom generators can loop indefinitely when size is zero — devDependency
8.5.15 — GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — devDependency
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 3118 files (highest-priority subset) · appwrite/appwrite
Dependency manifests: 6 package roots found, 6 scanned. PHP dependencies detected — dependency-CVE scanning does not cover it yet; CVEs there are UNVERIFIED, not absent.
[](https://nittim.com)