Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 2 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 2 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
2 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
500 of 27128 files scanned (1%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 27128 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 2 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
48.0.1 — GHSA-g6cj-pr64-35w5, GHSA-jwv3-5hgf-82ww
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing — HIGH
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building — HIGH
tests/components/http/test_auth.py:48
:48 — API_PASSWO…ord" — non-production path
tests/components/matrix/test_login.py:44, :55, :69
:44 — passwo…ord", — non-production path
:55 — passwo…ord", — non-production path
:69 — passwo…ord", — non-production path
tests/helpers/test_config_entry_oauth2_flow.py:30
:30 — REFRESH_TOKEN …ken" — non-production path
tests/scripts/test_auth.py:90
:90 — hass, provider, Mock(username="test-user", passwo…ass") — non-production path
tests/components/elmax/fixtures/cloud/login.json:2
:2 — "token": "JWT eyJhbG…ICv0", — non-production path
tests/components/elmax/fixtures/direct/login.json:2
:2 — "token": "JWT eyJhbG…50cA" — non-production path
tests/components/elmax/fixtures/login.json:2
:2 — "token": "JWT eyJhbG…ICv0", — non-production path
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 27128 files (highest-priority subset) · home-assistant/core
Dependency manifests: 1 package root found, 1 scanned; 4 Python manifests read.
[](https://nittim.com)