Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 30 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 30 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
30 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
166 of 186 files scanned (89%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 166 of 186 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 30 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
0.28.1 — GHSA-8cpq-38p9-67gx, GHSA-pv5w-4p9q-p3v2, GHSA-wmrf-hv6w-mr66
Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings — HIGH
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()` — HIGH
SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`. — HIGH
9.0.5 — GHSA-23c5-xmqv-rm74, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions — HIGH
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern — HIGH
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments — HIGH
15.3.1 — GHSA-267c-6grr-h53f, GHSA-26hh-7cqf-hhc6, GHSA-36qx-fr4f-26g5
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes — HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up — HIGH
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n — HIGH
0.39.0 — GHSA-7rqj-j65f-68wh, GHSA-xmf8-cvqr-rfgj
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass — CRITICAL
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers — HIGH
1.8.4 — GHSA-35jp-ww65-95wh, GHSA-3g43-6gmg-66jw
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` — HIGH
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge — HIGH
2.0.1 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
4.0.2 — GHSA-fjxv-7rqg-78g4, GHSA-hmw2-7cc7-3qxx
form-data uses unsafe random function in form-data for choosing boundary — CRITICAL
form-data: CRLF injection in form-data via unescaped multipart field names and filenames — HIGH
3.3.11 — GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8
nanoid: non-secure generators can loop indefinitely with negative size — HIGH
nanoid: custom generators can loop indefinitely when size is zero — HIGH
5.0.0-beta.27 — GHSA-7rqj-j65f-68wh, GHSA-8fpg-xm3f-6cx3
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass — CRITICAL
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) — CRITICAL
1.2.6 — GHSA-2vg6-77g8-24mp, GHSA-36rg-gfq2-3h56, GHSA-569q-mpph-wgww
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows — LOW
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes — LOW
Better Auth affected by external request basePath modification DoS — LOW
6.14.0 — GHSA-6rw7-vpxm-498p, GHSA-q8mj-m7cp-5q26, GHSA-w7fw-mjwx-w883
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion — MODERATE
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set — MODERATE
qs's arrayLimit bypass in comma parsing allows denial of service — LOW
4.17.21 — GHSA-f23m-r3pf-42rh, GHSA-xxjr-mmjv-4gpg
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` — MODERATE
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions — MODERATE
8.5.3 — GHSA-fxqj-rqcc-2cmp, GHSA-qx2v-qp2m-jg93
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — MODERATE
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 166 of 186 files · R44VC0RP/agenda.dev
Dependency manifests: 2 package roots found, 2 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)