Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 4 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 4 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
4 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
33 of 58 files scanned (56%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 33 of 58 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 4 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
3.13 — GHSA-8q59-q68h-6hv4, GHSA-rprw-h62v-c2w7
Improper Input Validation in PyYAML — CRITICAL
PyYAML insecurely deserializes YAML strings leading to arbitrary code execution — CRITICAL
3.5.3 — GHSA-2fqr-mr3j-6wp8, GHSA-2vrm-gr82-f7m5, GHSA-3wq7-rqq7-wx6j
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence — LOW
AIOHTTP has CRLF injection through multipart part content type header construction — LOW
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS — LOW
2.8 — GHSA-65pc-fj4g-8rjx, GHSA-jjg7-2v4v-x38h
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix — MODERATE
Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode — MODERATE
2.10 — GHSA-cpwx-vrp4-4pq7, GHSA-g3rq-g295-4j3m
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method — MODERATE
Regular Expression Denial of Service (ReDoS) in Jinja2 — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 33 of 58 files · anxolerd/dvpwa
Dependency manifests: 1 Python manifest read.
[](https://nittim.com)