Loading report…
← nittim
The secret and dependency scanners surfaced nothing verdict-bearing in what they scanned. This is not a clean bill of health. These two scanners cover a sliver of production-readiness — the 14 dimensions that actually decide whether you ship are unaudited below. Run Audit for the verdict.
The checks for leaked passwords and known package bugs found nothing to flag. This does not mean your code is safe. These two checks cover only a small slice of what matters — the 14 areas that actually decide whether your code is ready to ship are not checked yet. Run Audit for the full verdict.
No deterministic issues found — not a clean bill of health. 14 dimensions remain unaudited. Run Audit for the verdict.
484 of 21435 files scanned (2%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Read 484 of 500 selected files — this repository's archive was too large to finish in one scan.
Two scanners read 484 of 21435 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. Neither found anything. That is not a clean bill of health. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
20.0.0 — GHSA-39pv-4j6c-2g6v, GHSA-48r7-hpm6-gfxm, GHSA-58c5-g7wp-6w37
@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning — devDependency
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate) — devDependency
Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client — devDependency
20.0.0 — GHSA-58w9-8g37-x9v5, GHSA-f3m7-gqxr-g87x, GHSA-g93w-mfhg-p222
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS) — devDependency
Angular: Template and Attribute Namespace Sanitization Bypass (XSS) — devDependency
Angular vulnerable to XSS in i18n attribute bindings — devDependency
20.0.0 — GHSA-692r-grfm-v8x7, GHSA-f3m7-gqxr-g87x, GHSA-g93w-mfhg-p222
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) — devDependency
Angular: Template and Attribute Namespace Sanitization Bypass (XSS) — devDependency
Angular vulnerable to XSS in i18n attribute bindings — devDependency
2.0.1 — GHSA-3jxr-9vmj-r5cp, GHSA-f886-m6hf-6m8v, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — devDependency
brace-expansion: Zero-step sequence causes process hang and memory exhaustion — devDependency
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — devDependency
3.0.6 — GHSA-4c8g-83qw-93j6, GHSA-7p8r-x3mc-p8w7, GHSA-q3j6-qgpj-74h6
fast-uri vulnerable to host confusion via failed IDN canonicalization — devDependency
fast-uri vulnerable to host confusion via backslash authority introducer — devDependency
fast-uri vulnerable to path traversal via percent-encoded dot segments — devDependency
5.1.2 — GHSA-v56q-mh7h-f735, GHSA-wf6x-7x77-mvgw, GHSA-xvcm-6775-5m9r
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS — devDependency
Immutable is vulnerable to Prototype Pollution — devDependency
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set — devDependency
4.1.0 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68
js-yaml: YAML merge-key chains can force quadratic CPU consumption — devDependency
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — devDependency
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases — devDependency
3.0.5 — GHSA-64mm-vxmg-q3vj, GHSA-gcq2-9pq2-cxqm
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass — devDependency
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` — devDependency
0.5.5 — GHSA-5p2g-fcmc-qvqq, GHSA-w3rx-r6r6-pgpr
image-size: JXL and HEIF parsers allow denial of service through infinite loops — devDependency
image-size: ICNS parser allows denial of service through an infinite loop — devDependency
9.0.5 — GHSA-mwp4-54f8-5fhr, GHSA-v2v4-37r5-5v8g
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — devDependency
ip-address has XSS in Address6 HTML-emitting methods — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 484 of 21435 files (highest-priority subset) · metabase/metabase
Dependency manifests: 7 package roots found, 7 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)