Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 1 committed production secret and 3 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 1 password or key found in code that ships to production and 3 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
1 committed secret and 3 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
116 of 121 files scanned (95%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 116 of 121 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 1 committed credential on production paths and 3 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
1.1.11 — GHSA-3jxr-9vmj-r5cp, GHSA-f886-m6hf-6m8v, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — devDependency
brace-expansion: Zero-step sequence causes process hang and memory exhaustion — devDependency
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — devDependency
4.1.0 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68
js-yaml: YAML merge-key chains can force quadratic CPU consumption — devDependency
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — devDependency
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases — devDependency
3.1.2 — GHSA-23c5-xmqv-rm74, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions — devDependency
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern — devDependency
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments — devDependency
3.3.7 — GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8, GHSA-mwcw-c2x4-8c55
nanoid: non-secure generators can loop indefinitely with negative size — devDependency
nanoid: custom generators can loop indefinitely when size is zero — devDependency
Predictable results in nanoid generation when given non-integer values — devDependency
8.4.47 — GHSA-6g55-p6wh-862q, GHSA-fxqj-rqcc-2cmp, GHSA-qx2v-qp2m-jg93
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments — devDependency
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — devDependency
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output — devDependency
6.27.0 — GHSA-2j2x-hqr9-3h42, GHSA-337j-9hxr-rhxg, GHSA-9jcx-v3wj-wh4m
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation — MODERATE
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration — MODERATE
React Router has unexpected external redirect via untrusted paths — MODERATE
5.4.10 — GHSA-356w-63v5-8wf4, GHSA-4r4m-qw57-chr8, GHSA-4w7w-66w2-5vf9
Vite has an `server.fs.deny` bypass with an invalid `request-target` — devDependency
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query — devDependency
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling — devDependency
3.3.1 — GHSA-25h7-pfq9-p65f, GHSA-rf6f-7fwh-wjgh
flatted vulnerable to unbounded recursion DoS in parse() revive phase — devDependency
Prototype Pollution via parse() in NodeJS flatted — devDependency
4.17.21 — GHSA-f23m-r3pf-42rh, GHSA-xxjr-mmjv-4gpg
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — MODERATE
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions — MODERATE
2.3.1 — GHSA-3v7f-55p6-f55p, GHSA-c2c7-rcm5-vvqj
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching — devDependency
Picomatch has a ReDoS vulnerability via extglob quantifiers — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 116 of 121 files · aggwrk/nihongo-blocks
Dependency manifests: 1 package root found, 1 scanned.
[](https://nittim.com)