Loading report…
← nittim
The secret and dependency scanners surfaced nothing verdict-bearing in what they scanned. This is not a clean bill of health. These two scanners cover a sliver of production-readiness — the 14 dimensions that actually decide whether you ship are unaudited below. Run Audit for the verdict.
The checks for leaked passwords and known package bugs found nothing to flag. This does not mean your code is safe. These two checks cover only a small slice of what matters — the 14 areas that actually decide whether your code is ready to ship are not checked yet. Run Audit for the full verdict.
No deterministic issues found — not a clean bill of health. 14 dimensions remain unaudited. Run Audit for the verdict.
48 of 160 files scanned (30%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 48 of 160 files: one for committed credentials, one for known vulnerabilities in your dependencies. Neither found anything. That is not a clean bill of health. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.1.11 — GHSA-3jxr-9vmj-r5cp, GHSA-f886-m6hf-6m8v, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — devDependency
brace-expansion: Zero-step sequence causes process hang and memory exhaustion — devDependency
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — devDependency
4.1.2 — GHSA-2cf5-4w76-r9qv, GHSA-2qvq-rjwj-gvw9, GHSA-2w6w-674q-4c4q
Arbitrary Code Execution in handlebars — devDependency
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection — devDependency
Handlebars.js has JavaScript Injection via AST Type Confusion — devDependency
3.13.1 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68
js-yaml: YAML merge-key chains can force quadratic CPU consumption — devDependency
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — devDependency
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases — devDependency
4.17.20 — GHSA-29mw-wpgm-hmr9, GHSA-35jh-r3h4-6jhm, GHSA-f23m-r3pf-42rh
Regular Expression Denial of Service (ReDoS) in lodash — devDependency
Command Injection in lodash — devDependency
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — devDependency
3.0.4 — GHSA-23c5-xmqv-rm74, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions — devDependency
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern — devDependency
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments — devDependency
1.2.2 — GHSA-6rw7-vpxm-498p, GHSA-gqgv-6jq5-jjj9, GHSA-hrpp-h998-j3pp
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion — devDependency
Prototype Pollution Protection Bypass in qs — devDependency
qs vulnerable to Prototype Pollution — devDependency
6.10.2 — GHSA-2g4f-4pwh-qvx6, GHSA-v88g-cgmw-v5xw
ajv has ReDoS when using `$data` option — devDependency
Prototype Pollution in Ajv — devDependency
1.15.0 — GHSA-jxfh-8wgv-vfr2, GHSA-m8gw-hjpr-rjv7
Prototype pollution in dojo — devDependency
Prototype Pollution in dojo — devDependency
0.1.4 — GHSA-fjxv-7rqg-78g4, GHSA-hmw2-7cc7-3qxx
form-data uses unsafe random function in form-data for choosing boundary — devDependency
form-data: CRLF injection in form-data via unescaped multipart field names and filenames — devDependency
1.2.2 — GHSA-8r6j-v8pm-fqw3, MAL-2023-462
Code injection in fsevents — devDependency
Malicious code in fsevents (npm) — devDependency
1.1.1 — GHSA-44pw-h2cw-w3vq, GHSA-jcpv-g9rr-qxrc
Uncontrolled Resource Consumption in Hawk — devDependency
Regular Expression Denial of Service in hawk — devDependency
0.9.1 — GHSA-c429-5p7v-vgjp, GHSA-jp4x-w63m-7wgm
hoek subject to prototype pollution via the clone function. — devDependency
Prototype Pollution in hoek — devDependency
3.4.1 — GHSA-gxr4-xjj5-5px2, GHSA-jpcq-cgw6-v4j6
Potential XSS vulnerability in jQuery — devDependency
Potential XSS vulnerability in jQuery — devDependency
1.2.0 — GHSA-vh95-rmgr-6w4m, GHSA-xvch-5gv4-984h
Prototype Pollution in minimist — devDependency
Prototype Pollution in minimist — devDependency
4.4.10 — GHSA-23hp-3jrh-7fpw, GHSA-34x7-hfp2-rc4v
node-tar: Decompression/parse DoS via unlimited input — devDependency
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 48 of 160 files · lodash/lodash
Dependency manifests: 1 package root found, 1 scanned.
[](https://nittim.com)