Scan timing: clone 4.15s · analysis 8.59s · 6.9 MB · GitHub API rate-limit (preflight)
https://github.com/sveltejs/svelte
· scanned 2026-06-05 07:08 UTC (5 days, 23 hours ago)
· 10 languages
1192 raw signals (62 security + 1130 graph) 11/13 scanners ran 81st percentile · Javascript · large (100-500K LoC) System graph score 75 (higher by 10)
Last scanned 5 days, 23 hours ago · v2 · 567 actionable findings from 2 signal sources. 60 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
88.0 | 0.15 | 13.20 |
practices_score |
87.0 | 0.15 | 13.05 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 85.2 |
Showing 428 of 567 actionable findings. 627 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/svelte/src/compiler/phases/2-analyze/css/css-analyze.js:55packages/svelte/src/compiler/phases/2-analyze/visitors/ExportNamedDeclaration.js:57packages/svelte/src/compiler/phases/2-analyze/visitors/ExportSpecifier.js:19.github/workflows/pkg.pr.new.yml:31, 39, 53, 69, 74, 104, 120, 126, +3 more (15 hits).github/workflows/ci.yml:35, 37, 51, 53, 68, 70, 85, 87, +2 more (10 hits).github/workflows/ecosystem-ci-trigger.yml:20, 59, 109, 118 (8 hits).github/workflows/autofix.yml:31, 49, 54 (4 hits).github/workflows/release.yml:26, 32 (4 hits).github/workflows/pkg.pr.new.yml
CI/CD securitySupply chainGithub actions
packages/svelte/src/internal/server/hydratable.js:27
.well-known/security.txt
.github/workflows/autofix.yml
CI/CD securitySupply chainGithub actions
.github/workflows/release.yml
CI/CD securitySupply chainGithub actions
packages/svelte/src/compiler/phases/3-transform/client/visitors/UseDirective.js:21packages/svelte/src/compiler/phases/3-transform/server/visitors/ClassBody.js:2packages/svelte/src/compiler/phases/3-transform/server/visitors/DeclarationTag.js:14packages/svelte/src/compiler/phases/3-transform/server/visitors/VariableDeclaration.js:102packages/svelte/src/compiler/phases/3-transform/server/visitors/shared/component.js:25packages/svelte/src/internal/server/context.js:6packages/svelte/src/store/index-server.js:5llms.txt
humans.txt
robots.txt
sitemap.xml
playgrounds/sandbox/package.json
CI/CD securitySupply chainNpm
Showing first 300 of 428. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/39da5584-b756-4d91-a62c-f67af07c51a5/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/39da5584-b756-4d91-a62c-f67af07c51a5/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.