https://github.com/frappe/erpnext.git
· scanned 2026-05-20 01:10 UTC (2 weeks, 2 days ago)
· 10 languages
932 findings (95 legacy + 837 scanner) 11/13 scanners ran 66th percentile · Python · medium (20-100K LoC) Scanner says 71 (lower by 3)
Last scanned 2 weeks, 2 days ago · v3 · 374 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
40.0 | 0.20 | 8.00 |
documentation_score |
63.0 | 0.15 | 9.45 |
practices_score |
64.0 | 0.15 | 9.60 |
code_quality |
69.0 | 0.10 | 6.90 |
| Overall | 1.00 | 68.0 |
Showing 294 of 374 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
erpnext/accounts/doctype/bank_transaction_rule/bank_transaction_rule.py:117
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:120
qualitylegacy
erpnext/accounts/custom/address.py:47
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:138
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:137
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:126
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:141
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:145
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:135
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:149
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:117
qualitylegacy
erpnext/accounts/custom/address.py:26
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:128
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:122
qualitylegacy
erpnext/accounts/custom/address.py:20
qualitylegacy
erpnext/accounts/custom/address.py:28
qualitylegacy
erpnext/accounts/custom/address.py:31
qualitylegacy
erpnext/accounts/custom/address.py:31
qualitylegacy
erpnext/accounts/custom/address.py:48
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:134
qualitylegacy
erpnext/accounts/custom/address.py:13
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:157
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:156
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:116
qualitylegacy
erpnext/accounts/custom/address.py:12
qualitylegacy
erpnext/accounts/doctype/accounts_settings/accounts_settings.py:132
qualitylegacy
.github/workflows/patch.yml:92
dependencylegacy
.github/workflows/patch.yml:78
dependencylegacy
.github/workflows/patch.yml:69
dependencylegacy
.github/workflows/generate-pot-file.yml:24
dependencylegacy
.github/workflows/semantic-commits.yml:18
dependencylegacy
.github/workflows/docs-checker.yml:21
dependencylegacy
.github/workflows/patch.yml:41
dependencylegacy
.github/workflows/label-base-on-title.yml:15
dependencylegacy
.github/workflows/labeller.yml:14
dependencylegacy
.github/workflows/generate-pot-file.yml:34
dependencylegacy
.github/workflows/semantic-commits.yml:21
dependencylegacy
.github/workflows/patch.yml:60
dependencylegacy
.github/workflows/generate-pot-file.yml:29
dependencylegacy
.github/workflows/docs-checker.yml:16
dependencylegacy
.github/workflows/patch.yml:52
dependencylegacy
.github/workflows/docker-release.yml:13
dependencylegacy
.github/workflows/patch.yml:32
dependencylegacy
banking/src/components/features/BankReconciliation/BankEntryModal.tsx:255
owaspeval_used
banking/src/components/features/BankReconciliation/Rules/RuleForm.tsx:452
owaspeval_used
erpnext/accounts/doctype/bank_transaction_rule/bank_transaction_rule.py:117
error_handlinglegacy
erpnext/accounts/doctype/bank_statement_import/bank_statement_import.py:162
qualitylegacy
erpnext/accounts/doctype/bank_statement_import_log/bank_statement_import_log.js:8
securitylegacy
banking/src/pages/BankStatementImporter.tsx:237
securitylegacy
banking/src/components/common/LinkFieldCombobox.tsx:246
securitylegacy
.github/workflows/linters.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/generate-pot-file.yml
supply-chaingithub-actionsleast-privilege
banking/src/components/features/BankReconciliation/BankClearanceSummary.tsx:210
owaspdangerous_innerhtml
banking/src/components/features/BankReconciliation/BankReconciliationStatement.tsx:196
owaspdangerous_innerhtml
banking/src/components/features/BankReconciliation/BankTransactionList.tsx:250
owaspdangerous_innerhtml
banking/src/components/features/BankReconciliation/IncorrectlyClearedEntries.tsx:184
owaspdangerous_innerhtml
banking/src/components/ui/textarea.tsx:12
qualitylegacy
banking/src/components/ui/select.tsx:24
qualitylegacy
banking/src/components/features/BankReconciliation/TransferModal.tsx:180
qualitylegacy
banking/src/components/features/BankReconciliation/Rules/RuleForm.tsx:444
qualitylegacy
banking/src/components/features/BankReconciliation/MatchAndReconcile.tsx:137
qualitylegacy
.github/workflows/label-base-on-title.yml:15
supply-chaingithub-actionspinned-dependencies
.github/workflows/patch.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/patch.yml:52
supply-chaingithub-actionspinned-dependencies
.github/workflows/patch.yml:60
supply-chaingithub-actionspinned-dependencies
.github/workflows/patch.yml:69
supply-chaingithub-actionspinned-dependencies
.github/workflows/patch.yml:78
supply-chaingithub-actionspinned-dependencies
.github/workflows/docs-checker.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/docs-checker.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/generate-pot-file.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/generate-pot-file.yml:29
supply-chaingithub-actionspinned-dependencies
.github/workflows/generate-pot-file.yml:34
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/backport.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/linters.yml:33
supply-chaingithub-actionspinned-dependencies
package.json
supply-chainnpminstall-scripts
erpnext/projects/doctype/task/task.py:318
dead-code
erpnext/subcontracting/doctype/subcontracting_bom/subcontracting_bom.py:35
dead-code
erpnext/manufacturing/doctype/bom_creator/bom_creator.py:73
dead-code
erpnext/manufacturing/doctype/bom_creator/bom_creator.py:163
dead-code
erpnext/commands/__init__.py:7
dead-code
erpnext/__init__.py:178
dead-code
erpnext/deprecation_dumpster.py:87
dead-code
erpnext/projects/doctype/task/task.py:296
dead-code
erpnext/erpnext_integrations/utils.py:11
dead-code
erpnext/projects/doctype/project/project.py:187
dead-code
erpnext/__init__.py:58
dead-code
erpnext/erpnext_integrations/utils.py:10
dead-code
banking/proxyOptions.ts:10
qualitylegacy
banking/src/components/ui/dropdown-menu.tsx:63
qualitylegacy
banking/src/components/features/BankReconciliation/IncorrectlyClearedEntries.tsx:184
qualitylegacy
.github/helper/documentation.py:44
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/7bfa3179-7646-4f6c-9965-6c3558bc8cc9/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/7bfa3179-7646-4f6c-9965-6c3558bc8cc9/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.