https://github.com/wekan/wekan.git
· scanned 2026-05-22 09:04 UTC (1 week, 6 days ago)
· 10 languages
849 findings (183 legacy + 666 scanner) 11/13 scanners ran 22nd percentile · Javascript · large (100-500K LoC) Scanner says 55 (higher by 21)
Last scanned 1 week, 6 days ago · v2 · 516 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
39.0 | 0.20 | 7.80 |
documentation_score |
90.0 | 0.15 | 13.50 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
57.0 | 0.10 | 5.70 |
| Overall | 1.00 | 76.0 |
Showing 407 of 516 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
stacksmith/user-scripts/boot.sh:11
qualitylegacy
docs/Platforms/FOSS/Docker/Meteor3/1createdb.sh:63
qualitylegacy
openapi/generate_openapi.py:490
qualitylegacy
releases/translations/old-pull-translations.sh:150
dependencylegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:112
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:93
dockerlegacy
Dockerfile:15
dockerlegacy
.devcontainer/Dockerfile:15
dockerlegacy
api.py:87
secrets
docs/Platforms/FOSS/OpenShift/wekan.yml:34
secrets
docs/Platforms/FOSS/OpenShift/wekan.yml:36
secrets
releases/install-sandstorm.sh:4
qualitylegacy
openapi/generate_openapi.py:115
qualitylegacy
openapi/generate_openapi.py:113
qualitylegacy
openapi/generate_openapi.py:104
qualitylegacy
openapi/generate_openapi.py:165
qualitylegacy
openapi/generate_openapi.py:419
qualitylegacy
openapi/generate_openapi.py:344
qualitylegacy
openapi/generate_openapi.py:396
qualitylegacy
openapi/generate_openapi.py:324
qualitylegacy
openapi/generate_openapi.py:179
qualitylegacy
openapi/generate_openapi.py:185
qualitylegacy
openapi/generate_openapi.py:182
qualitylegacy
openapi/generate_openapi.py:414
qualitylegacy
openapi/generate_openapi.py:449
qualitylegacy
openapi/generate_openapi.py:399
qualitylegacy
openapi/generate_openapi.py:392
qualitylegacy
openapi/generate_openapi.py:460
qualitylegacy
openapi/generate_openapi.py:460
qualitylegacy
openapi/generate_openapi.py:458
qualitylegacy
openapi/generate_openapi.py:417
qualitylegacy
openapi/generate_openapi.py:416
qualitylegacy
openapi/generate_openapi.py:427
qualitylegacy
openapi/generate_openapi.py:429
qualitylegacy
openapi/generate_openapi.py:258
qualitylegacy
openapi/generate_openapi.py:271
qualitylegacy
openapi/generate_openapi.py:301
qualitylegacy
.github/workflows/release-all.yml:108
dependencylegacy
.github/workflows/release-all.yml:101
dependencylegacy
.github/workflows/release-all.yml:96
dependencylegacy
.github/workflows/release-all.yml:43
dependencylegacy
.github/workflows/playwright.yml:137
dependencylegacy
.github/workflows/playwright.yml:58
dependencylegacy
.github/workflows/playwright.yml:18
dependencylegacy
.github/workflows/release-all.yml:471
dependencylegacy
.github/workflows/release-all.yml:422
dependencylegacy
.github/workflows/release-all.yml:300
dependencylegacy
.github/workflows/release-all.yml:234
dependencylegacy
.github/workflows/release-all.yml:174
dependencylegacy
.github/workflows/release-all.yml:409
dependencylegacy
.github/workflows/release-all.yml:120
dependencylegacy
.github/workflows/playwright.yml:140
dependencylegacy
.github/workflows/playwright.yml:61
dependencylegacy
.github/workflows/playwright.yml:21
dependencylegacy
.github/workflows/release-all.yml:456
dependencylegacy
.github/workflows/release-all.yml:337
dependencylegacy
.github/workflows/release-all.yml:271
dependencylegacy
.github/workflows/release-all.yml:205
dependencylegacy
.github/workflows/release-all.yml:141
dependencylegacy
.github/workflows/playwright.yml:115
dependencylegacy
.github/workflows/playwright.yml:107
dependencylegacy
.github/workflows/release-all.yml:477
dependencylegacy
.gitpod.Dockerfile:1
dependencylegacy
.devcontainer/Dockerfile:1
dependencylegacy
Dockerfile:1
dependencylegacy
.github/workflows/playwright.yml:128
dependencylegacy
.github/workflows/playwright.yml:49
dependencylegacy
packages/wekan-accounts-cas/cas_server.js:63
xxelegacy
models/avatars.js:43
qualitylegacy
models/attachments.js:41
qualitylegacy
client/components/settings/translationBody.js:106
qualitylegacy
server/models/activities.js:171
qualitylegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:147
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:709
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:112
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:93
dockerlegacy
docker-compose.yml:265
dockerlegacy
docker-compose.yml:224
dockerlegacy
.devcontainer/docker-compose.yml:18
dockerlegacy
.devcontainer/docker-compose.yml:4
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:112
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:709
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:112
dockerlegacy
server/models/activities.js:313
error_handlinglegacy
client/components/unicode-icons.js:66
error_handlinglegacy
client/00-startup.js:15
error_handlinglegacy
openapi/generate_openapi.py:811
qualitylegacy
api.py:785
qualitylegacy
api.py:568
qualitylegacy
api.py:412
qualitylegacy
api.py:389
qualitylegacy
packages/wekan-accounts-cas/cas_client_cordova.js:65
securitylegacy
packages/wekan-accounts-cas/cas_client.js:115
securitylegacy
packages/wekan-accounts-cas/cas_client.js:51
open_redirectlegacy
config/accounts.js:128
open_redirectlegacy
models/csvCreator.js:310
qualitylegacy
client/components/gantt/gantt.js:110
qualitylegacy
docker-compose.yml:265
dockerlegacy
.devcontainer/docker-compose.yml:4
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:709
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:112
dockerlegacy
docker-compose.yml:224
dockerlegacy
.devcontainer/docker-compose.yml:4
dockerlegacy
client/components/swimlanes/swimlanes.js:106
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
docs/Platforms/FOSS/Source/Source.md:23
dependencylegacy
docs/Platforms/FOSS/Source/Install-from-source-without-root.md:10
dependencylegacy
docs/Platforms/FOSS/Sandstorm/Developing-Wekan-for-Sandstorm.md:15
dependencylegacy
docs/Platforms/FOSS/Sandstorm/Building-Wekan-for-Sandstorm.md:62
dependencylegacy
docs/DeveloperDocs/Debugging.md:99
dependencylegacy
docs/Databases/FerretDB2-PostgreSQL.md:28
dependencylegacy
README.md:127
dependencylegacy
.travis.yml:12
dependencylegacy
.github/workflows/release-all.yml:127
dependencylegacy
.github/workflows/playwright.yml:27
dependencylegacy
public/robots.txt
qualitylegacy
.github/workflows/release-all.yml:226
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:292
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:477
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docker-publish.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
docker-compose.yml
securityports
releases/build-cache/http/phpdevserver.sh
securityports
releases/snapcraft-local.yaml
securityports
.dockerignore
dockerlegacy
npm-packages/meteor-jade-loader/index.js:30
qualitylegacy
models/server/metrics.js:220
qualitylegacy
docs/ImportExport/trello/api.py:155
qualitylegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:147
dockerlegacy
.devcontainer/docker-compose.yml:18
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:147
dockerlegacy
docker-compose.yml:265
dockerlegacy
docs/Databases/ToroDB-PostgreSQL/docker-compose.yml:147
dockerlegacy
docker-compose.yml:265
dockerlegacy
.devcontainer/docker-compose.yml:18
dockerlegacy
models/exportPDF.js:37
qualitylegacy
models/exportPDF.js:32
qualitylegacy
models/exportExcel.js:31
qualitylegacy
models/customFields.js:76
qualitylegacy
models/checklists.js:23
qualitylegacy
models/checklists.js:21
qualitylegacy
models/checklists.js:20
qualitylegacy
models/checklistItems.js:24
qualitylegacy
models/cardComments.js:26
qualitylegacy
models/cardComments.js:23
qualitylegacy
models/avatars.js:20
qualitylegacy
models/announcements.js:17
qualitylegacy
models/announcements.js:6
qualitylegacy
models/accountSettings.js:16
qualitylegacy
imports/lib/secureDOMPurify.js:5
qualitylegacy
config/query-classes.js:5
qualitylegacy
config/query-classes.js:2
qualitylegacy
client/lib/pasteImage.js:36
qualitylegacy
client/lib/filter.js:7
qualitylegacy
client/lib/filter.js:4
qualitylegacy
client/config/blazeHelpers.js:18
qualitylegacy
client/config/blazeHelpers.js:14
qualitylegacy
client/components/users/userHeader.js:264
qualitylegacy
client/components/swimlanes/swimlanes.js:569
qualitylegacy
client/components/swimlanes/swimlanes.js:412
qualitylegacy
client/components/swimlanes/swimlaneHeader.js:45
qualitylegacy
client/components/settings/adminReports.js:243
qualitylegacy
client/components/rules/actions/checklistActions.js:45
qualitylegacy
client/components/lists/listHeader.js:343
qualitylegacy
client/components/cards/cardDate.js:9
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
public/robots.txt
qualitylegacy
Dockerfile:1
supply-chaindockerpinned-dependencies
.devcontainer/Dockerfile:1
supply-chaindockerpinned-dependencies
.github/workflows/playwright.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yml:61
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yml:107
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yml:115
supply-chaingithub-actionspinned-dependencies
.github/workflows/playwright.yml:140
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:101
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:108
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:174
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:234
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:300
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:422
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-all.yml:471
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-publish.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/depsreview.yaml:12
supply-chaingithub-actionspinned-dependencies
.github/workflows/depsreview.yaml:14
supply-chaingithub-actionspinned-dependencies
packages/wekan-fontawesome/fontawesome-free/package.json
supply-chainnpminstall-scripts
Showing first 300 of 407. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/5937a6d5-bde9-481f-adad-93b0de1062da/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5937a6d5-bde9-481f-adad-93b0de1062da/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.