Free CRA readiness check
We read your public pages and, if you add one, a public GitHub repository. You get a report on your security.txt, your disclosure policy, the dependencies you ship and your support period. When we cannot verify something from outside, we say so instead of guessing.
Only public pages and public files are read.
security.txt
Missing at /.well-known/security.txt
Vulnerable dependencies
guzzlehttp/psr7 2.4.3, CVE-2026-48998
SECURITY.md
Disclosure policy with contact