https://github.com/TypeCellOS/BlockNote
· scanned 2026-05-15 21:15 UTC (2 weeks, 6 days ago)
· 10 languages
341 findings (38 legacy + 303 scanner) 47th percentile · Typescript · large (100-500K LoC) Scanner says 56 (higher by 19)
Last scanned 2 weeks, 6 days ago · v1 · 34 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
90.6 | 0.25 | 22.65 |
testing_score |
60.0 | 0.20 | 12.00 |
documentation_score |
85.0 | 0.15 | 12.75 |
practices_score |
80.0 | 0.15 | 12.00 |
code_quality |
60.0 | 0.10 | 6.00 |
| Overall | 1.00 | 74.4 |
Showing 32 of 34 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docs/app/llms-full.txt/route.ts:6
authlegacy
docs/app/llms.mdx/[[...slug]]/route.ts:11
authlegacy
docs/app/llms.txt/route.ts:5
authlegacy
packages/xl-odt-exporter/src/odt/odtExporter.tsx:243
injectionlegacy
react-dangerously-set-html
· CWE-79
· A03:2021
packages/xl-odt-exporter/src/odt/odtExporter.tsx:236
injectionlegacy
react-dangerously-set-html
· CWE-79
· A03:2021
packages/react/src/components/FormattingToolbar/ExperimentalMobileFormattingToolbarController.tsx:76
injectionlegacy
react-dangerously-set-html
· CWE-79
· A03:2021
packages/react/src/components/Popovers/GenericPopover.tsx:175
injectionlegacy
react-dangerously-set-html
· CWE-79
· A03:2021
docs/app/(home)/_components/ui/FeatureWindow.tsx:68
injectionlegacy
react-dangerously-set-html
· CWE-79
· A03:2021
packages/xl-odt-exporter/src/odt/odtExporter.tsx:197
cryptolegacy
http-not-https
· CWE-319
· A02:2021
docs/redirects.ts:252
qualitylegacy
docs/redirects.ts:247
qualitylegacy
docs/components/Footer.tsx:125
qualitylegacy
docs/components/Footer.tsx:120
qualitylegacy
packages/mantine/src/comments/Editor.tsx:1
qualitylegacy
packages/mantine/src/comments/Comment.tsx:6
qualitylegacy
packages/mantine/src/badge/Badge.tsx:12
qualitylegacy
packages/core/vite.config.ts:39
qualitylegacy
packages/core/vite.config.ts:23
qualitylegacy
packages/core/src/editor/defaultColors.ts:2
qualitylegacy
packages/core/src/blocks/ListItem/NumberedListItem/block.ts:58
qualitylegacy
packages/core/src/blocks/Image/block.ts:25
qualitylegacy
packages/core/src/api/exporters/html/util/serializeBlocksInternalHTML.ts:33
qualitylegacy
packages/code-block/vite.config.ts:26
qualitylegacy
packages/ariakit/src/sideMenu/SideMenuButton.tsx:8
qualitylegacy
packages/react/src/components/Comments/ThreadsSidebar.tsx:179
qualitylegacy
magic-number-default
packages/mantine/src/defaultThemes copy.ts:1
qualitylegacy
packages/react/src/components/Comments/Comment.tsx:44
qualitylegacy
todo-bomb
packages/react/src/components/Comments/Thread.tsx:64
qualitylegacy
todo-bomb
packages/mantine/src/defaultThemes copy.ts:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/5f7e4eb4-3fc5-4e04-b8c8-9bed19543eed/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5f7e4eb4-3fc5-4e04-b8c8-9bed19543eed/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.