Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 2 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 2 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
2 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
84 of 130 files scanned (64%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 84 of 130 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 2 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
1.11.7 — GHSA-337x-4q8g-prc5, GHSA-3gh2-xw74-jmcw
Improper Input Validation in Django — HIGH
SQL injection in Django — HIGH
3.7.3 — GHSA-fx83-3ph3-9j2q, GHSA-gw84-84pc-xp82, PYSEC-2020-263
Cross-site Scripting (XSS) in Django REST Framework — MODERATE
Cross-site Scripting in djangorestframework — LOW
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come f — UNKNOWN
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 84 of 130 files · payatu/Tiredful-API
Dependency manifests: 1 Python manifest read.
[](https://nittim.com)