ai model report

Is morsetechlab/yolov11-license-plate-detection safe to load?

HIGH risk. 2 of 58 tracked dependencies carry advisories, 1 malicious. Driven by pulls ultralytics, which has known-malicious releases, without pinning a version.

View on HuggingFace

// posture
advisories 100provenance 100resolution 100xyz safety 15load safety 20supply chain 35scanner trust 55code execution 100
fig. 01 — posture on eight axes, 100 is clean. Weakest: xyz safety at 15.
// the finding
8.5xyz score out of 10HIGH

HIGHUses package(s) with known-malicious releases, but pins no version — the installed version decides whether this is a compromise: ultralytics (malicious at 8.3.41, 8.3.42, 8.3.43, 8.3.44, 8.3.45)

1 more finding on this model.

Author
morsetechlab
Task
object-detection
Loader
ultralytics
License
agpl-3.0
Downloads
81,560
Remote code
not required
// dependencies

4 direct, 3 with findings, 54 reachable, 1 malicious

PackageEvidenceAdvisoriesWorst
ultralyticsmaliciousdirect, runtime0CRITICAL
opencv-pythondirect, inferred31none pinned
Create a free accountto see all 58 dependencies, which versions are pinned, and what to change.

Risk computed 2026-10-01 at 23:49 UTC. Dependencies come from the model's requirements, its declared loader and the code it ships; advisories from NVD, GHSA and OSV.

Model risk is computed from the model's declared and observed Python dependencies and the code it ships. If a finding is wrong, tell us.