https://github.com/microsoft/PowerToys
· scanned 2026-06-05 04:55 UTC (11 hours, 8 minutes ago)
· 10 languages
202 findings (84 legacy + 118 scanner) 11/13 scanners ran Scanner says 92 (lower by 24)
Last scanned 11 hours, 8 minutes ago · v2 · 143 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
12.0 | 0.20 | 2.40 |
documentation_score |
90.0 | 0.15 | 13.50 |
practices_score |
71.0 | 0.15 | 10.65 |
code_quality |
71.0 | 0.10 | 7.10 |
| Overall | 1.00 | 68.4 |
Showing 90 of 143 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/Monaco/monacoSRC/min/vs/basic-languages/sparql/sparql.js:8
qualitylegacy
src/Monaco/monacoSRC/min/vs/basic-languages/hcl/hcl.js:8
qualitylegacy
src/modules/cmdNotFound/CmdNotFoundModuleInterface/dllmain.cpp:57
qualitylegacy
.github/workflows/telemetry-pr-check.yml:30
dependencylegacy
.github/workflows/manual-batch-issue-deduplication.yml:30
dependencylegacy
.github/workflows/dependency-review.yml:24
dependencylegacy
.github/workflows/dependency-review.yml:26
dependencylegacy
.github/workflows/auto-label-issues.yml:31
dependencylegacy
.github/workflows/msstore-submissions.yml:43
dependencylegacy
.github/workflows/msstore-submissions.yml:50
dependencylegacy
.github/workflows/msstore-submissions.yml:26
dependencylegacy
.github/workflows/msstore-submissions.yml:46
dependencylegacy
.github/workflows/manual-batch-issue-deduplication.yml:33
dependencylegacy
.github/workflows/automatic-issue-deduplication.yml:16
dependencylegacy
installer/PowerToysSetupVNext/WebView2/MicrosoftEdgeWebview2Setup.exe:1
dependencylegacy
src/common/FilePreviewCommon/Formatters/XmlFormatter.cs:23
xxelegacy
src/modules/cmdpal/Microsoft.CmdPal.UI/Settings/InternalPage.SampleData.cs:32
secretlegacy
src/Monaco/monacoSRC/min/vs/basic-languages/javascript/javascript.js:8
redoslegacy
src/Monaco/monacoSRC/min/vs/basic-languages/java/java.js:8
redoslegacy
src/Monaco/monacoSRC/min/vs/basic-languages/apex/apex.js:8
redoslegacy
src/modules/cmdpal/ext/Microsoft.CmdPal.Ext.Indexer/Helpers/DataPackageHelper.cs:85
qualitylegacy
.dockerignore
dockerlegacy
.github/workflows/msstore-submissions.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/msstore-submissions.yml:50
supply-chaingithub-actionspinned-dependencies
.github/workflows/automatic-issue-deduplication.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/manual-batch-issue-deduplication.yml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/spelling2.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/msstore-submissions.yml
supply-chaingithub-actionsleast-privilege
src/Monaco/monacoSRC/min/vs/basic-languages/mysql/mysql.js:8
owaspweak_hash
src/modules/cmdpal/Microsoft.CmdPal.Common/Helpers/InternalListHelpers.cs:140
qualitylegacy
src/modules/MouseWithoutBorders/App/Core/Launch.cs:112
qualitylegacy
src/modules/CropAndLock/CropAndLock/ThumbnailCropAndLockWindow.cpp:34
qualitylegacy
src/modules/CropAndLock/CropAndLock/ReparentCropAndLockWindow.cpp:4
qualitylegacy
src/modules/AdvancedPaste/AdvancedPaste/Helpers/NativeMethods.cs:54
qualitylegacy
src/common/utils/json.h:6
qualitylegacy
src/common/Telemetry/TraceBase.h:21
qualitylegacy
src/common/Telemetry/EtwTrace/EtwTrace.cpp:8
qualitylegacy
src/Update/PowerToys.Update.cpp:1
qualitylegacy
.github/workflows/msstore-submissions.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/dependency-review.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/dependency-review.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/auto-label-issues.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/manual-batch-issue-deduplication.yml:30
supply-chaingithub-actionspinned-dependencies
.github/workflows/telemetry-pr-check.yml:30
supply-chaingithub-actionspinned-dependencies
src/modules/cmdpal/Microsoft.CmdPal.UI.ViewModels/Commands/CreatedExtensionForm.cs:72
qualitylegacy
src/modules/MouseWithoutBorders/App/Helper/Program.cs:67
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/5bbaf307-4009-4846-ae56-f38d6ab4b085/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5bbaf307-4009-4846-ae56-f38d6ab4b085/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.