Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 1 committed production secret and 1 high/critical dependency vulnerability. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 1 password or key found in code that ships to production and 1 serious security bug in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
1 committed secret and 1 critical dependency vulnerability found. 11 more dimensions need Audit for the full picture.
500 of 27113 files scanned (1%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 500 of 27113 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 1 committed credential on production paths and 1 high or critical vulnerability in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
packages/@n8n/ai-workflow-builder.ee/evaluations/__tests__/webhook.test.ts:70, :80, :100, :117, :125, :138, :146, :581, :611, :695
:70 — const secret…234'; — non-production path
:80 — const secret…234'; — non-production path
:100 — const secret…678'; — non-production path
:117 — const secret…234'; — non-production path
:125 — const secret…234'; — non-production path
:138 — const secret…234'; — non-production path
:146 — const secret…234'; — non-production path
:581 — webhookSecret…234', — non-production path
:611 — const secret…234'; — non-production path
:695 — webhookSecret…234', — non-production path
packages/@n8n/api-types/src/dto/auth/__tests__/login-request.dto.test.ts:10, :18, :25, :34, :50, :65, :80
:10 — passwo…123', — non-production path
:18 — passwo…123', — non-production path
:25 — passwo…123', — non-production path
:34 — passwo…123', — non-production path
:50 — passwo…123', — non-production path
:65 — passwo…123', — non-production path
:80 — passwo…123', — non-production path
packages/@n8n/api-types/src/dto/password-reset/__tests__/change-password-request.dto.test.ts:9, :10, :16, :17, :31, :36, :41, :46, :52, :60, :68, :69, :76, :77, :94, :95, :105, :106
:9 — token:…gth', — non-production path
:10 — passwo…123', — non-production path
:16 — token:…ken', — non-production path
:17 — passwo…123', — non-production path
:31 — request: { passwo…123' }, — non-production path
:36 — request: { token: '', passwo…123' }, — non-production path
:41 — request: { token: 'short', passwo…123' }, — non-production path
:46 — request: { token:…ken' }, — non-production path
:52 — token:…ken', — non-production path
:60 — token:…ken', — non-production path
:68 — token:…ken', — non-production path
:69 — passwo…ord', — non-production path
:76 — token:…ken', — non-production path
:77 — passwo…123', — non-production path
:94 — token:…ken', — non-production path
:95 — passwo…123', — non-production path
:105 — token:…)_+', — non-production path
:106 — passwo…123', — non-production path
packages/@n8n/api-types/src/dto/password-reset/__tests__/resolve-password-token-query.dto.test.ts:8
:8 — request: { token:…ken' }, — non-production path
packages/@n8n/api-types/src/dto/user/__tests__/password-update-request.dto.test.ts:6, :18, :30, :31, :41, :42
:6 — newPasswo…123', — non-production path
:18 — currentPasswo…123', — non-production path
:30 — currentPasswo…123', — non-production path
:31 — newPasswo…123', — non-production path
:41 — currentPasswo…123', — non-production path
:42 — newPasswo…123', — non-production path
packages/@n8n/client-oauth2/test/config.ts:6, :9
:6 — export const accessToken …403'; — non-production path
:9 — export const refreshedRefreshToken …ndt'; — non-production path
packages/@n8n/client-oauth2/test/credential-options.test.ts:14, :28
:14 — client…ret', — non-production path
:28 — client…ret', — non-production path
packages/@n8n/ai-workflow-builder.ee/evaluations/__tests__/webhook.test.ts:158, :318
:158 — validateWebhookUrl('https:…/xxx'), — non-production path
:318 — expect(() => validateWebhookUrl('https:…/xxx')).not.toThrow(); — non-production path
8.0.2 — GHSA-4w7w-66w2-5vf9, GHSA-fx2h-pf6j-xcff, GHSA-p9ff-h696-f583
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling — devDependency
vite: `server.fs.deny` bypass on Windows alternate paths — devDependency
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket — devDependency
13.0.2 — GHSA-38c4-r59v-3vqw, GHSA-6v5v-wf23-fmfq
markdown-it is has a Regular Expression Denial of Service (ReDoS) — MODERATE
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 500 of 27113 files (highest-priority subset) · n8n-io/n8n
Dependency manifests: 89 package roots found, 6 scanned; 2 Python manifests read — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)