https://github.com/payloadcms/payload
· scanned 2026-05-16 13:37 UTC (1 day, 7 hours ago)
· 10 languages
1367 findings (172 legacy + 1195 scanner) 8/10 scanners ran 17th percentile · Typescript · huge (>500K LoC)
Last scanned 3 days, 4 hours ago · v1 · 1365 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
23.7 | 0.25 | 5.92 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
74.0 | 0.15 | 11.10 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 68.0 |
web: 3.0 ·
authz: 10.6 ·
docker: 140.4 ·
threat: 12.8 ·
journey: 44.4
Showing 258 of 1365 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
templates/ecommerce/src/app/(app)/(account)/orders/page.tsx:38
error_handlinglegacy
templates/with-vercel-website/src/utilities/getMediaUrl.ts:7
qualitylegacy
templates/with-vercel-website/src/endpoints/seed/index.ts:43
qualitylegacy
templates/website/src/utilities/getMediaUrl.ts:7
qualitylegacy
templates/website/src/endpoints/seed/index.ts:43
qualitylegacy
templates/ecommerce/src/endpoints/seed/index.ts:87
qualitylegacy
packages/plugin-mcp/src/index.ts:93
qualitylegacy
packages/plugin-mcp/src/index.ts:92
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:197
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:161
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:159
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:137
qualitylegacy
packages/plugin-ecommerce/src/collections/carts/endpoints/updateItem.ts:40
qualitylegacy
packages/plugin-ecommerce/src/collections/carts/endpoints/updateItem.ts:34
qualitylegacy
packages/plugin-ecommerce/src/collections/carts/endpoints/updateItem.ts:28
qualitylegacy
packages/payload/src/config/types.ts:239
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
packages/drizzle/src/countGlobalVersions.ts:21
qualitylegacy
packages/db-vercel-postgres/src/types.ts:29
qualitylegacy
packages/db-vercel-postgres/src/index.ts:159
qualitylegacy
packages/db-vercel-postgres/src/index.ts:11
qualitylegacy
packages/db-vercel-postgres/src/index.ts:3
qualitylegacy
packages/db-vercel-postgres/src/connect.ts:81
qualitylegacy
packages/db-vercel-postgres/src/connect.ts:47
qualitylegacy
packages/db-vercel-postgres/scripts/renamePredefinedMigrations.ts:1
qualitylegacy
packages/db-sqlite/src/types.ts:10
qualitylegacy
packages/db-sqlite/src/index.ts:10
qualitylegacy
packages/db-sqlite/src/index.ts:1
qualitylegacy
packages/db-sqlite/src/exports/types-deprecated.ts:1
qualitylegacy
packages/db-sqlite/src/connect.ts:34
qualitylegacy
packages/db-sqlite/bundle.js:1
qualitylegacy
packages/db-postgres/src/index.ts:2
qualitylegacy
packages/db-postgres/bundle.js:9
qualitylegacy
packages/db-mongodb/src/updateVersion.ts:31
qualitylegacy
packages/codemod/src/transforms/migrate-import-export-hooks/non-matching.output.ts:1
qualitylegacy
packages/db-mongodb/src/updateOne.ts:66
qualitylegacy
packages/db-mongodb/src/updateOne.ts:35
qualitylegacy
packages/db-mongodb/src/updateMany.ts:50
qualitylegacy
packages/db-mongodb/src/queryDrafts.ts:79
qualitylegacy
packages/db-mongodb/src/queries/parseParams.ts:8
qualitylegacy
packages/db-mongodb/src/findVersions.ts:75
qualitylegacy
packages/db-mongodb/src/findVersions.ts:50
qualitylegacy
packages/db-mongodb/src/findGlobalVersions.ts:67
qualitylegacy
packages/db-mongodb/src/createVersion.ts:77
qualitylegacy
packages/db-mongodb/src/countVersions.ts:25
qualitylegacy
packages/db-mongodb/src/countGlobalVersions.ts:21
qualitylegacy
.github/actions/activity/src/popular-issues.ts:18
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
.github/actions/activity/pnpm-lock.yaml
qualitylegacy
packages/db-mongodb/src/predefinedMigrations/migrateVersionsV1_V2.ts:1
qualitylegacy
packages/db-mongodb/src/predefinedMigrations/migrateRelationshipsV2_V3.ts:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/836245fa-286f-4238-953c-95e0eac60349/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/836245fa-286f-4238-953c-95e0eac60349/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.