Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 30 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 30 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
30 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
60 of 70 files scanned (85%). Nothing was cut short by a limit — the rest is mostly images, generated output, and other non-source content this audit doesn't read.
Two scanners read 60 of 70 files: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 30 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep AI is the tier that issues a verdict. This scan does not.
0.8.11 — GHSA-2v35-w6hq-6mfw, GHSA-f6ww-3ggp-fr8h, GHSA-j759-j44w-7fr8
xmldom: Uncontrolled recursion in XML serialization leads to DoS — HIGH
xmldom has XML injection through unvalidated DocumentType serialization — HIGH
xmldom has XML node injection through unvalidated comment serialization — HIGH
1.0.11 — GHSA-6433-x5p4-8jc7, GHSA-jv72-59wq-8rxm, GHSA-mg49-jqgw-gcj6
libxmljs vulnerable to type confusion when parsing specially crafted XML — CRITICAL
libxmljs has segmentation fault, potentially leading to a denial-of-service (DoS) — HIGH
libxmljs vulnerable to type confusion when parsing specially crafted XML — CRITICAL
5.1.6 — GHSA-23c5-xmqv-rm74, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions — HIGH
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern — HIGH
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments — HIGH
6.2.1 — GHSA-23hp-3jrh-7fpw, GHSA-34x7-hfp2-rc4v, GHSA-83g3-92jg-28cx
node-tar: Decompression/parse DoS via unlimited input — CRITICAL
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal — HIGH
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction — HIGH
2.0.2 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
4.1.1 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj
js-yaml: YAML merge-key chains can force quadratic CPU consumption — HIGH
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — HIGH
3.10.3 — GHSA-248r-7h7q-cr24, GHSA-47x8-96vw-5wg6
vm2 Has a Sandbox Breakout Using Async Generator — CRITICAL
vm2 Access to Host Object Enables Sandbox Escape — CRITICAL
1.8.3 — GHSA-2qqx-w9hr-q5gx, GHSA-2vrf-hf26-jrp5
angular vulnerable to regular expression denial of service via the $resource service — MODERATE
angular vulnerable to regular expression denial of service via the angular.copy() utility — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 60 of 70 files · snoopysecurity/dvws-node
Dependency manifests: 1 package root found, 1 scanned — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)