Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 2 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 2 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
2 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
500 of 2027 files scanned (24%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 2027 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 2 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.1.16 — GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — HIGH
test/plausible_web/controllers/auth_controller_test.exs:38, :46, :61, :70, :84, :93, :128, :141, :159, :177, :194, :216, :245, :277, :1387, :1388, :1418, :1419, :1450, :1451, :1466, :1467
:38 — passwo…123", — non-production path
:46 — passwo…123", — non-production path
:61 — passwo…123", — non-production path
:70 — passwo…123", — non-production path
:84 — passwo…123", — non-production path
:93 — passwo…123", — non-production path
:128 — passwo…123", — non-production path
:141 — passwo…123", — non-production path
:159 — passwo…123", — non-production path
:177 — passwo…123", — non-production path
:194 — passwo…123", — non-production path
:216 — passwo…123", — non-production path
:245 — passwo…123", — non-production path
:277 — passwo…123", — non-production path
:1387 — access_token:…ken", — non-production path
:1388 — refresh_token:…ken", — non-production path
:1418 — access_token:…ken", — non-production path
:1419 — refresh_token:…ken", — non-production path
:1450 — access_token:…ken", — non-production path
:1451 — refresh_token:…ken", — non-production path
:1466 — access_token:…ken", — non-production path
:1467 — refresh_token:…ken", — non-production path
test/plausible/auth/totp_test.exs:158, :184, :195, :213, :234, :247, :263, :280, :304, :311, :370, :383, :402
:158 — user = insert(:user, passwo…ret") — non-production path
:184 — user = insert(:user, passwo…ret") — non-production path
:195 — user = insert(:user, passwo…ret") — non-production path
:213 — user = insert(:user, passwo…ret") — non-production path
:234 — user = insert(:user, passwo…ret") — non-production path
:247 — user = insert(:user, passwo…ret") — non-production path
:263 — user2 = insert(:user, passwo…ret") — non-production path
:280 — user = insert(:user, passwo…ret") — non-production path
:304 — user = insert(:user, passwo…ret") — non-production path
:311 — user = insert(:user, passwo…ret") — non-production path
:370 — user = insert(:user, passwo…ret") — non-production path
:383 — user = insert(:user, passwo…ret") — non-production path
:402 — user = insert(:user, passwo…ret") — non-production path
test/plausible/auth/user_test.exs:90, :103, :128, :140
:90 — passwo…gle" — non-production path
:103 — |> change(passwo…gle") — non-production path
:128 — passwo…123", — non-production path
:140 — passwo…asd", — non-production path
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 2027 files (highest-priority subset) · plausible/analytics
Dependency manifests: 4 package roots found, 4 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)