Scan timing: clone 4.42s · analysis 64.55s · 11.5 MB · GitHub preflight 420ms
https://github.com/thedaviddias/Front-End-Checklist
· scanned 2026-06-05 08:06 UTC (5 days, 20 hours ago)
· 10 languages
493 raw signals (147 security + 346 graph) 15th percentile · Typescript · medium (20-100K LoC) System graph score 67 (lower by 14)
Last scanned 5 days, 20 hours ago · v2 · 173 actionable findings from 2 signal sources. 147 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
11.5 | 0.25 | 2.88 |
testing_score |
72.0 | 0.20 | 14.40 |
documentation_score |
50.8 | 0.15 | 7.62 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
58.1 | 0.10 | 5.81 |
| Overall | 1.00 | 53.8 |
Showing 143 of 173 actionable findings. 320 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/audit/mcp-impact-benchmark.ts:113
packages/validators/src/validate-security.ts:36
packages/content/rules/en/html/clean-up-comments.mdx:565packages/content/rules/en/security/leaked-secrets.mdx:121skills/clean-up-comments/references/rule.md:497skills/leaked-secrets/references/rule.md:31apps/web/app/api/checklists/[id]/route.ts:76
apps/web/app/api/checklists/[id]/route.ts:22
packages/validators/src/validate-types.ts:51
.github/workflows/ci.yml:18, 26, 42, 50, 69, 77, 96, 104, +5 more (26 hits).github/workflows/pr.yml:55, 65, 101, 109, 137, 145, 172, 180, +6 more (14 hits).github/workflows/e2e.yml:25, 33, 57, 65, 73, 86, 89, 113 (8 hits).github/workflows/deploy.yml:19, 27 (4 hits).github/workflows/ci.yml:21, 45, 72, 99, 126, 146, 174 (14 hits).github/workflows/deploy.yml:22, 56, 71 (6 hits).github/workflows/pr.yml:60, 104, 140, 175, 238, 273 (6 hits).github/workflows/e2e.yml:28.github/workflows/ci.yml:283
CI/CD securitySupply chainGithub actions
packages/validators/src/validate-security.ts:36
Eval used
scripts/audit/mcp-impact-benchmark.ts:113
Eval used
pnpm-lock.yaml
apps/web/app/api/account/route.ts:12
apps/web/app/api/audits/route.ts:77
apps/web/app/api/fix-suggestion/route.ts:8
apps/web/app/api/profile/route.ts:13
apps/web/app/api/progress/route.ts:11
apps/web/app/api/profile/route.ts:31
apps/web/app/api/audits/route.ts:28
apps/web/app/api/progress/route.ts:110
apps/web/app/api/progress/route.ts:35
apps/web/hooks/use-user-checklists.ts:173
scripts/validation/check-as-casts.js:200
apps/web/app/(site)/(account)/settings/settings-page-client.tsx:29, 51 (2 hits)apps/web/app/api/checklists/[id]/route.ts:65, 102 (2 hits)apps/web/app/api/checklists/[id]/share/route.ts:34, 66 (2 hits)apps/web/app/api/mcp/route.ts:299, 364 (2 hits)apps/web/app/(site)/(account)/profile/profile-form.tsx:147apps/web/app/(site)/(account)/profile/profile-page-client.tsx:20apps/web/app/(site)/audits/audits-page-client.tsx:31apps/web/app/api/audits/route.ts:69pnpm-lock.yaml
.well-known/security.txt
docs/audit-comparison/README.md:42
pnpm-lock.yaml
packages/analytics/providers/openpanel.tsx:41
Dangerous innerhtml
packages/design-system/src/custom/navigation/breadcrumb.tsx:146
Dangerous innerhtml
packages/seo/src/structured-data.ts:134
Dangerous innerhtml
packages/validators/src/validate-security.ts:43
Dangerous innerhtml
apps/web/components/homepage/category-card.tsx:129, 131 (2 hits)packages/mcp/src/tools/search-rules.ts:32, 36 (2 hits)packages/types/src/index.ts:3, 4 (2 hits)apps/web/app/(site)/(account)/settings/settings-page-shell.tsx:6apps/web/app/(site)/rules/[category]/[slug]/rule-page-support.tsx:11apps/web/app/(site)/u/[username]/public-profile-client.tsx:215apps/web/components/checklists/actions/add-to-checklist-dropdown.tsx:124apps/web/components/checklists/browser/checklist-card.tsx:172apps/web/package.jsonpackages/data-layer/package.jsonpackages/virtualization/package.json
apps/web/package.jsonpackages/search/package.jsonapps/web/package.json
humans.txt
apps/web/lib/server/github-import-update.ts:1
package.json
CI/CD securitySupply chainNpm
packages/auth/package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/44e4ee1f-a4a7-44b3-95ef-0df7bb1822af/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/44e4ee1f-a4a7-44b3-95ef-0df7bb1822af/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.