Loading report…
← nittim
The secret and dependency scanners surfaced nothing verdict-bearing in what they scanned. This is not a clean bill of health. These two scanners cover a sliver of production-readiness — the 14 dimensions that actually decide whether you ship are unaudited below. Run Audit for the verdict.
The checks for leaked passwords and known package bugs found nothing to flag. This does not mean your code is safe. These two checks cover only a small slice of what matters — the 14 areas that actually decide whether your code is ready to ship are not checked yet. Run Audit for the full verdict.
No deterministic issues found — not a clean bill of health. 14 dimensions remain unaudited. Run Audit for the verdict.
142 of 236 files scanned (60%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 142 of 236 files: one for committed credentials, one for known vulnerabilities in your dependencies. Neither found anything. That is not a clean bill of health. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
3.1.2 — GHSA-cpwx-vrp4-4pq7, GHSA-gmj6-6f8f-6699, GHSA-h5c8-rqwp-cp95
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method — devDependency
Jinja has a sandbox breakout through malicious filenames — devDependency
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter — devDependency
2.3.3 — GHSA-29vq-49wr-vm6x, GHSA-2g68-c3qc-8985, GHSA-87hc-h4r5-73f7
Werkzeug safe_join() allows Windows special device names — devDependency
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain — devDependency
Werkzeug safe_join() allows Windows special device names with compound extensions — devDependency
2.3.2 — GHSA-68rp-wp8r-4726, PYSEC-2026-2151
Flask session does not add `Vary: Cookie` header when accessed in some ways — devDependency
Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Us — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 142 of 236 files · pallets/flask
Dependency manifests: 5 Python manifests read.
[](https://nittim.com)