Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 3 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 3 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
3 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
448 of 28694 files scanned (1%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Read 448 of 500 selected files — this repository's archive was too large to finish in one scan.
Two scanners read 448 of 28694 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 3 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
packages/twenty-apps/public/fireflies/src/logic-functions/utils/__tests__/verify-fireflies-webhook-signature.test.ts:7
:7 — const SECRET…123'; — non-production path
packages/twenty-apps/public/slack/src/__tests__/constants/slack-test-webhook-secret.constant.ts:1
:1 — export const SLACK_TEST_WEBHOOK_SECRET…ret'; — non-production path
packages/twenty-front/src/modules/apollo/utils/__tests__/getTokenPair.test.ts:69, :81, :82, :97, :113, :129, :144, :148, :163, :177, :182, :227
:69 — refreshToken: { token:…ken' }, — non-production path
:81 — accessOrWorkspaceAgnosticToken:…ect', — non-production path
:82 — refreshToken: { token:…ken' }, — non-production path
:97 — refreshToken: { token:…ken' }, — non-production path
:113 — refreshToken: { token:…ken' }, — non-production path
:129 — refreshToken: { token:…ken' }, — non-production path
:144 — token:…ken', — non-production path
:148 — token:…ken', — non-production path
:163 — token:…ken', — non-production path
:177 — token:…ras', — non-production path
:182 — token:…ken', — non-production path
:227 — const unicodeToken …s-∑'; — non-production path
packages/twenty-front/src/modules/apollo/utils/__tests__/hasTokenPair.test.ts:19, :23, :38, :42, :57, :62, :102, :117, :121, :142, :158, :162
:19 — token:…ken', — non-production path
:23 — token:…ken', — non-production path
:38 — token:…ken', — non-production path
:42 — token:…ken', — non-production path
:57 — token:…ken', — non-production path
:62 — token:…ken', — non-production path
:102 — token:…ken', — non-production path
:117 — token:…lid', — non-production path
:121 — token:…ken', — non-production path
:142 — token:…ken', — non-production path
:158 — token:…ken', — non-production path
:162 — token:…ken', — non-production path
packages/twenty-front/src/modules/auth/components/__tests__/VerifyEmail.test.tsx:95, :99
:95 — token:…ken', — non-production path
:99 — token:…ken', — non-production path
packages/twenty-front/src/modules/auth/components/__tests__/VerifyLoginTokenEffect.test.tsx:27, :31
:27 — token:…ken', — non-production path
:31 — token:…ken', — non-production path
packages/twenty-front/src/modules/auth/hooks/__tests__/useRedeemSSOExchangeToken.test.ts:34, :38, :45, :49, :79
:34 — token:…ken', — non-production path
:38 — token:…ken', — non-production path
:45 — token:…ken', — non-production path
:49 — token:…ken', — non-production path
:79 — variables: { ssoExchangeToken:…ken' }, — non-production path
packages/twenty-front/src/modules/auth/hooks/__tests__/useVerifyLogin.test.ts:47, :51
:47 — token:…ken', — non-production path
:51 — token:…ken', — non-production path
packages/twenty-front/src/modules/auth/services/__tests__/AuthService.test.ts:14
:14 — token:…ken', — non-production path
packages/twenty-front/src/modules/auth/sign-in-up/components/internal/SignInUpWorkspaceScopeFormEffect.tsx:20
:20 — RequestingCaptchaToken …ken', — non-production path
packages/twenty-front/src/modules/auth/sign-in-up/hooks/__tests__/useHandleResetPassword.test.ts:97, :117
:97 — captchaToken:…ken', — non-production path
:117 — captchaToken:…ken', — non-production path
packages/twenty-front/src/modules/auth/sign-in-up/hooks/__tests__/useSignInUp.test.tsx:96
:96 — captchaToken:…ken', — non-production path
packages/twenty-front/src/modules/auth/sign-in-up/hooks/__tests__/useSignInUpForm.test.tsx:77
:77 — passwo…dev', — non-production path
.github/workflows/ci-create-app-e2e-minimal.yaml:55
:55 — TWENTY_API_KEY: eyJhbG…Idik — non-production path
.github/workflows/ci-example-app-hello-world.yaml:54
:54 — TWENTY_API_KEY: eyJhbG…Idik — non-production path
.github/workflows/ci-example-app-postcard.yaml:56
:56 — TWENTY_API_KEY: eyJhbG…Idik — non-production path
.github/workflows/ci-sdk.yaml:70
:70 — TWENTY_API_KEY: eyJhbG…Idik — non-production path
packages/twenty-front/src/modules/auth/hooks/__mocks__/useAuth.ts:21
:21 — 'eyJhbG…sw5c'; — non-production path
packages/twenty-server/.env.test:15
:15 — ENTERPRISE_VALIDITY_TOKEN=eyJhbG…Kvdg — non-production path
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 448 of 28694 files (highest-priority subset) · twentyhq/twenty
Dependency manifests: 36 package roots found, 27 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)