Scan timing: clone 18.91s · analysis 19.62s · 26.4 MB · GitHub API rate-limit (preflight)
https://github.com/mercurjs/mercur
· scanned 2026-05-19 14:54 UTC (2 weeks, 3 days ago)
· 10 languages
761 findings (77 legacy + 684 scanner) 8/10 scanners ran 25th percentile · Typescript · large (100-500K LoC) Scanner says 82 (lower by 13)
Last scanned 2 weeks, 3 days ago · v3 · 305 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
30.0 | 0.20 | 6.00 |
documentation_score |
76.0 | 0.15 | 11.40 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 69.2 |
Showing 53 of 305 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/cli/src/utils/build-vendor-extensions.ts:74
xsslegacy
packages/cli/src/registry/errors.ts:195
xsslegacy
packages/admin/src/pages/orders/order-list/components/order-list-table/order-list-data-table.tsx:58
xsslegacy
This page is publicly accessible at:
https://repobility.com/scan/11a59421-a7a1-4fb7-a18e-f00276c92e73/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/11a59421-a7a1-4fb7-a18e-f00276c92e73/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.