Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 8 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 8 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
8 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
465 of 23852 files scanned (1%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Read 465 of 500 selected files — this repository's archive was too large to finish in one scan.
Two scanners read 465 of 23852 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 8 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
1.12.0 — GHSA-35jp-ww65-95wh, GHSA-3g43-6gmg-66jw
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` — HIGH
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge — HIGH
1.13.1 — GHSA-35jp-ww65-95wh, GHSA-3g43-6gmg-66jw
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` — HIGH
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge — HIGH
8.5.10 — GHSA-6g55-p6wh-862q, GHSA-r28c-9q8g-f849
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments — HIGH
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure — HIGH
8 — GHSA-566m-qj78-rww5, GHSA-6g55-p6wh-862q, GHSA-7fh5-64p2-3v2j
Regular Expression Denial of Service in postcss — devDependency
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments — devDependency
PostCSS line return parsing error — devDependency
8.5.10 — GHSA-fxqj-rqcc-2cmp
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — MODERATE
10.9.0 — GHSA-2v8p-3f2j-5mp7, GHSA-6m6c-36f7-fhxh, GHSA-6x64-9x62-f2gx
Mermaid XY Charts are vulnerable to an infinite loop DoS — MODERATE
Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS — MODERATE
Mermaid allows CSS injection applying to sibling elements of the diagram — MODERATE
1.12.0 — GHSA-3p68-rc4w-qgx5
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF — MODERATE
1.13.1 — GHSA-3p68-rc4w-qgx5
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF — MODERATE
1.6.3 — GHSA-3qcw-2rhx-2726, GHSA-hcf7-66rw-9f5r
Turbo: Unexpected local code execution during Yarn Berry detection — devDependency
Turbo: Login callback CSRF/session fixation — devDependency
2.1.8 — GHSA-5xrq-8626-4rwp, GHSA-9crc-q9x8-hgqq
When Vitest UI server is listening, arbitrary file can be read and executed — devDependency
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening — devDependency
2.3.1 — GHSA-48c2-rrv3-qjmp
yaml is vulnerable to Stack Overflow via deeply nested YAML collections — MODERATE
2.7.0 — GHSA-48c2-rrv3-qjmp
yaml is vulnerable to Stack Overflow via deeply nested YAML collections — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 465 of 23852 files (highest-priority subset) · medusajs/medusa
Dependency manifests: 100 package roots found, 98 scanned.
[](https://nittim.com)