Scan timing: clone 7.71s · analysis 4.4s · 33.7 MB · GitHub API rate-limit (preflight)
https://github.com/zotero/web-library
· scanned 2026-06-05 14:52 UTC (5 days, 3 hours ago)
· 10 languages
316 raw signals (68 security + 248 graph) 11/13 scanners ran 91st percentile · Javascript · medium (20-100K LoC) System graph score 75 (higher by 10)
Last scanned 5 days, 3 hours ago · v2 · 148 actionable findings from 2 signal sources. 44 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
89.0 | 0.20 | 17.80 |
documentation_score |
55.0 | 0.15 | 8.25 |
practices_score |
82.0 | 0.15 | 12.30 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 84.1 |
Showing 78 of 148 actionable findings. 192 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/generate-fixtures.mjs:193
.github/workflows/ci.yml:23
.github/workflows/build.yml:25 (2 hits).github/workflows/ci.yml:8, 12, 28, 32, 38 (7 hits).github/workflows/build.yml:11, 15 (3 hits)index.html
.well-known/security.txt
src/js/component/common/table-cell.jsx:121
Dangerous innerhtml
src/js/component/modal/bibliography.jsx:310
Dangerous innerhtml
src/js/component/modal/copy-citation.jsx:906
Dangerous innerhtml
src/js/component/modal/copy-citation.jsx:584, 706 (2 hits)src/js/component/modal/metadata-retrieval.jsx:142, 143 (2 hits)src/js/component/modal/rename-collection.jsx:61, 63 (2 hits)src/js/component/item/actions/new-item.jsx:51src/js/component/item/items/table-row.jsx:183src/js/component/item/items/table.jsx:143src/js/component/library.jsx:34src/js/component/modal/add-by-identifier.jsx:63llms.txt
humans.txt
robots.txt
sitemap.xml
This page is publicly accessible at:
https://repobility.com/scan/6a9fbbec-f8ee-4107-b3a5-8557627a95cf/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/6a9fbbec-f8ee-4107-b3a5-8557627a95cf/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.