Scan timing: clone 8.49s · analysis 14.66s · 24.7 MB · GitHub preflight 459ms
https://github.com/phpbb/phpbb
· scanned 2026-05-20 15:04 UTC (2 weeks, 1 day ago)
· 10 languages
216 findings (116 legacy + 100 scanner)
Last scanned 2 weeks, 1 day ago · v2 · 166 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
48.8 | 0.25 | 12.20 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
68.6 | 0.15 | 10.29 |
practices_score |
87.0 | 0.15 | 13.05 |
code_quality |
50.0 | 0.10 | 5.00 |
| Overall | 1.00 | 66.5 |
Showing 108 of 166 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
phpBB/phpbb/console/command/user/activate.php:204
qualitylegacy
phpBB/includes/ucp/ucp_resend.php:147
qualitylegacy
phpBB/includes/ucp/ucp_activate.php:143
qualitylegacy
phpBB/phpbb/passwords/driver/bcrypt.php:61
cryptolegacy
phpBB/phpbb/passwords/driver/base_native.php:55
cryptolegacy
phpBB/phpbb/auth/provider/db.php:201
cryptolegacy
phpBB/phpbb/cache/driver/memory.php:31
qualitylegacy
phpBB/phpbb/cache/driver/base.php:100
qualitylegacy
phpBB/develop/benchmark.php:70
qualitylegacy
.github/setup-sphinx.sh:143
qualitylegacy
phpBB/phpbb/plupload/plupload.php:360
path_traversallegacy
.github/workflows/check_merge_to_master.yml:15
dependencylegacy
.github/workflows/merge_3.3.x_to_master.yml:20
dependencylegacy
.github/workflows/merge_3.3.x_to_master.yml:13
dependencylegacy
.github/workflows/check_merge_to_master.yml:55
dependencylegacy
.github/workflows/check_merge_to_master.yml:46
dependencylegacy
.devcontainer/Dockerfile:3
dependencylegacy
phpBB/styles/prosilver/template/ucp_register.html:45
authlegacy
phpBB/adm/style/auth_provider_oauth.html:14
authlegacy
.github/setup-sphinx.sh:143
owaspchmod_777
phpBB/phpbb/feed/helper.php:157
securitylegacy
phpBB/install/startup.php:188
securitylegacy
phpBB/assets/javascript/phpbb-avatars.js:245
open_redirectlegacy
.dockerignore
dockerlegacy
.devcontainer/Dockerfile:3
dockerlegacy
.github/workflows/check_merge_to_master.yml:46
supply-chaingithub-actionspinned-dependencies
.github/workflows/check_merge_to_master.yml:55
supply-chaingithub-actionspinned-dependencies
phpBB/assets/plupload/plupload.full.min.js:14
owaspcors_wildcard
phpBB/adm/style/permissions.js:119
qualitylegacy
phpBB/phpbb/db/extractor/oracle_extractor.php:184
qualitylegacy
phpBB/phpbb/db/driver/sqlite3.php:62
qualitylegacy
phpBB/phpbb/db/driver/postgres.php:114
qualitylegacy
phpBB/phpbb/db/driver/oracle.php:170
qualitylegacy
phpBB/phpbb/db/driver/mssqlnative.php:68
qualitylegacy
phpBB/phpbb/cron/task/core/tidy_warnings.php:4
qualitylegacy
phpBB/phpbb/console/command/user/add.php:63
qualitylegacy
phpBB/phpbb/console/command/searchindex/delete.php:1
qualitylegacy
phpBB/phpbb/console/command/extension/update.php:31
qualitylegacy
phpBB/phpbb/console/command/extension/remove.php:1
qualitylegacy
phpBB/phpbb/console/command/config/set_atomic.php:30
qualitylegacy
phpBB/phpbb/console/command/config/set_atomic.php:28
qualitylegacy
phpBB/phpbb/console/command/config/set.php:25
qualitylegacy
phpBB/phpbb/auth/provider/ldap.php:76
qualitylegacy
phpBB/phpbb/auth/provider/db.php:27
qualitylegacy
phpBB/includes/ucp/ucp_profile.php:489
qualitylegacy
phpBB/includes/ucp/ucp_pm.php:187
qualitylegacy
phpBB/includes/mcp/mcp_logs.php:116
qualitylegacy
phpBB/includes/acp/acp_main.php:467
qualitylegacy
phpBB/develop/generate_utf_tables.php:105
qualitylegacy
phpBB/develop/generate_utf_confusables.php:142
qualitylegacy
phpBB/develop/export_events_for_wiki.php:17
qualitylegacy
phpBB/develop/export_events_for_wiki.php:16
qualitylegacy
phpBB/develop/export_events_for_rst.php:17
qualitylegacy
phpBB/develop/adjust_usernames.php:21
qualitylegacy
phpBB/develop/adjust_uids.php:71
qualitylegacy
phpBB/develop/adjust_uids.php:53
qualitylegacy
phpBB/develop/adjust_smilies.php:1
qualitylegacy
phpBB/develop/adjust_sizes.php:27
qualitylegacy
phpBB/phpbb/db/migration/data/v33x/bot_update.php:45
qualitylegacy
build:1
qualitylegacy
git-tools/merge.php
qualitylegacy
phpBB/phpbb/install/module/requirements/task/check_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v400/storage_backup.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v400/search_backend_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v33x/topic_views_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v33x/profilefields_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v33x/profilefield_youtube_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v33x/jquery_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v33x/font_awesome_5_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v33x/bot_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v330/jquery_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v32x/jquery_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v320/icons_alt.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v320/font_awesome_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v31x/style_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v310/notifications_schema_fix.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v310/mod_rewrite.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v310/jquery_update.php:1
qualitylegacy
phpBB/phpbb/db/migration/data/v310/bot_update.php:1
qualitylegacy
phpBB/includes/acp/info/acp_update.php:1
qualitylegacy
phpBB/includes/acp/acp_update.php:1
qualitylegacy
.devcontainer/Dockerfile:3
supply-chaindockerpinned-dependencies
.github/workflows/check_merge_to_master.yml:15
supply-chaingithub-actionspinned-dependencies
.github/workflows/merge_3.3.x_to_master.yml:20
supply-chaingithub-actionspinned-dependencies
phpBB/develop/benchmark.php:30
qualitylegacy
phpBB/common.php:60
qualitylegacy
phpBB/adm/style/tooltip.js:6
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/39acd121-31dd-4d86-b94c-121eecd4031c/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/39acd121-31dd-4d86-b94c-121eecd4031c/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.