Scan timing: clone 13.3s · analysis 27.67s · 36.1 MB · GitHub API rate-limit (preflight)
https://github.com/facebook/react
· scanned 2026-06-05 04:28 UTC (11 hours, 47 minutes ago)
· 10 languages
2383 findings (123 legacy + 2260 scanner) 11/13 scanners ran 88th percentile · Javascript · large (100-500K LoC) Scanner says 41 (higher by 50)
Last scanned 11 hours, 47 minutes ago · v2 · 1253 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
99.0 | 0.15 | 14.85 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 90.8 |
Showing 35 of 1253 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
compiler/packages/react-mcp-server/src/utils/algolia.ts:14
secrets
compiler/packages/snap/src/sprout/evaluator.ts:255
owaspeval_used
fixtures/fiber-debugger/src/App.js:122
owaspeval_used
packages/react-devtools-extensions/src/evalScripts.js:20
owaspeval_used
packages/react-devtools-extensions/deploy.js:43
owaspexec_used
scripts/bench/build.js:18
owaspexec_used
scripts/ci/download_devtools_regression_build.js:40
owaspexec_used
scripts/devtools/prepare-release.js:85
owaspexec_used
scripts/devtools/publish-release.js:107
owaspexec_used
scripts/devtools/utils.js:90
owaspexec_used
scripts/release/build-release-locally-commands/build-artifacts.js:15
owaspexec_used
scripts/release/build-release-locally-commands/copy-repo-to-temp-directory.js:19
owaspexec_used
scripts/release/build-release-locally-commands/npm-pack-and-unpack.js:13
owaspexec_used
scripts/release/shared-commands/download-build-artifacts.js:26
owaspexec_used
scripts/release/utils.js:45
owaspexec_used
scripts/rollup/utils.js:31
owaspexec_used
scripts/shared/listChangedFiles.js:40
owaspexec_used
packages/react-devtools-shared/src/devtools/views/UnsupportedBridgeProtocolDialog.js:137
securitylegacy
packages/react-devtools-shared/src/devtools/views/Editor/OpenInEditorButton.js:66
securitylegacy
packages/react-devtools-shared/src/devtools/views/Components/OpenInEditorButton.js:41
securitylegacy
fixtures/attribute-behavior/src/attributes.js:398
owaspdangerous_innerhtml
fixtures/fizz/src/Html.js:21
owaspdangerous_innerhtml
fixtures/ssr/src/components/Chrome.js:24
owaspdangerous_innerhtml
fixtures/ssr2/src/Html.js:21
owaspdangerous_innerhtml
fixtures/view-transition/src/components/Chrome.js:29
owaspdangerous_innerhtml
packages/react-dom-bindings/src/client/ReactDOMComponent.js:637
owaspdangerous_innerhtml
packages/react-dom-bindings/src/client/ReactDOMOption.js:44
owaspdangerous_innerhtml
packages/react-dom-bindings/src/client/ReactFiberConfigDOM.js:164
owaspdangerous_innerhtml
packages/react-dom-bindings/src/server/ReactFizzConfigDOM.js:1623
owaspdangerous_innerhtml
packages/react-dom-bindings/src/shared/possibleStandardNames.js:49
owaspdangerous_innerhtml
packages/react-dom-bindings/src/shared/ReactDOMUnknownPropertyHook.js:104
owaspdangerous_innerhtml
scripts/error-codes/codes.json:61
owaspdangerous_innerhtml
packages/react-devtools-shell/src/app/Iframe/index.js:44
owaspdocument_write
This page is publicly accessible at:
https://repobility.com/scan/71490123-d37f-4659-ac2a-5b9a11374c25/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/71490123-d37f-4659-ac2a-5b9a11374c25/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.