Close Open Privacy Scan
App Privacy Score
Low risk · 252 finding(s)
Based on: 3 first-party package(s) · 14/16 deps analyzed
Dependency score: 72 (Medium risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz External domains
::ffff:192.168.0.1aws.amazon.combabel.pocoo.orgbrotlipy.readthedocs.iobugs.python.orgcdn.jsdelivr.netclick.palletsprojects.comcloud.google.comcommonmark.orgcurl.sedatatracker.ietf.orgdeveloper.mozilla.orgdiscuss.python.orgdocs.pydantic.devdocs.python.orgdocs.rsen.wikipedia.orgengineering.salesforce.comerrors.pydantic.devexam_ple.comfastapi.tiangolo.comfonts.googleapis.comfoo.comgithub.comgoogle-auth.readthedocs.iohtml.spec.whatwg.orghttpbin.orghypothesis.readthedocs.iojson-schema.orglocalhost.tiangolo.commypy.readthedocs.iomüller.denats.ioother.compackaging.python.orgpeps.python.orgpydantic-docs.helpmanual.iopypi.orgpython-devtools.helpmanual.ioraw.githubusercontent.comrequests.readthedocs.iorich.readthedocs.iosethmlarson.devspdx.devstackoverflow.comstarlette.devswagger.iotools.ietf.orgtyper.tiangolo.comunicode.orgunpkg.comwww.apache.orgwww.blackhat.comwww.example.珠宝www.google.comwww.iana.orgwww.loc.govwww.python.orgwww.rfc-editor.orgwww.unicode.orgwww.w3.orgwww.xudongz.comwww.youtube.comxn--fiqs8s.icom.museum
</> First-Party Code
first-party (python)
python first-partyexpand_more 17 low-confidence finding(s)
low env_fs — Filesystem access. 12 locations
low env_fs — Environment-variable access. 4 locations
response = self._session().post(url, **kwargs)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
</> Dependencies
typer
python dependency for value in track(range(100), description="Processing..."):
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
expand_more 66 low-confidence finding(s)
low env_fs — Filesystem access. 37 locations
low env_fs — Environment-variable access. 29 locations
babel
python dependencyexpand_more 33 low-confidence finding(s)
low env_fs — Filesystem access. 28 locations
low env_fs — Environment-variable access. 4 locations
with urlopen(request) as response:
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
curl-cffi
python dependencyexpand_more 14 low-confidence finding(s)
low env_fs — Filesystem access. 6 locations
low env_fs — Environment-variable access. 8 locations
fastapi
python dependencyexpand_more 70 low-confidence finding(s)
low env_fs — Filesystem access. 55 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 12 locations
os.environ["DYLD_FALLBACK_LIBRARY_PATH"] = "/opt/homebrew/lib"
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 2 locations
flights
python dependencyexpand_more 15 low-confidence finding(s)
low env_fs — Filesystem access. 10 locations
low env_fs — Environment-variable access. 4 locations
response = self._session().post(url, **kwargs)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
httpx
python dependencyexpand_more 4 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
plotext
python dependencyexpand_more 3 low-confidence finding(s)
low env_fs — Filesystem access. 3 locations
pydantic
python dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Filesystem access. 5 locations
pydantic-settings
python dependencyexpand_more 3 low-confidence finding(s)
return parse_env_vars(os.environ, self.case_sensitive, self.env_ignore_empty, self.env_parse_none_str)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low env_fs — Filesystem access. 2 locations
python-dotenv
python dependencyexpand_more 11 low-confidence finding(s)
low env_fs — Filesystem access. 3 locations
low env_fs — Environment-variable access. 8 locations
ratelimit
python dependencyexpand_more 1 low-confidence finding(s)
with open('README.rst') as infile:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
uvicorn
python dependencyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
low env_fs — Filesystem access. 2 locations
Skipped dependencies
Production
- fli-js prod — registry 404
- fastmcp prod — sdist exceeds byte cap