https://github.com/payloadcms/payload
· scanned 2026-05-16 13:37 UTC (1 day, 6 hours ago)
· 10 languages
1367 findings (172 legacy + 1195 scanner) 8/10 scanners ran 17th percentile · Typescript · huge (>500K LoC)
Last scanned 3 days, 3 hours ago · v1 · 1365 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
23.7 | 0.25 | 5.92 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
74.0 | 0.15 | 11.10 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 68.0 |
web: 3.0 ·
authz: 10.6 ·
docker: 140.4 ·
threat: 12.8 ·
journey: 44.4
Showing 47 of 1365 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
templates/ecommerce/src/app/(app)/next/preview/route.ts:43
credential_exposurelegacy
templates/with-vercel-website/src/app/(frontend)/next/preview/route.ts:43
credential_exposurelegacy
templates/website/src/app/(frontend)/next/preview/route.ts:43
credential_exposurelegacy
templates/website/next.config.ts:29
ssrflegacy
templates/with-vercel-website/next.config.ts:29
ssrflegacy
templates/ecommerce/next.config.ts:27
ssrflegacy
templates/with-vercel-website/docker-compose.yml:3
dockerlegacy
templates/with-postgres/docker-compose.yml:19
dockerlegacy
templates/with-vercel-website/docker-compose.yml:3
dockerlegacy
templates/with-vercel-postgres/docker-compose.yml:19
dockerlegacy
templates/with-vercel-mongodb/docker-compose.yml:19
dockerlegacy
templates/with-postgres/docker-compose.yml:19
dockerlegacy
templates/website/docker-compose.yml:17
dockerlegacy
templates/blank/docker-compose.yml:19
dockerlegacy
templates/_template/docker-compose.yml:19
dockerlegacy
examples/remix/payload/docker-compose.yml:19
dockerlegacy
examples/localization/docker-compose.yml:17
dockerlegacy
examples/astro/payload/docker-compose.yml:19
dockerlegacy
templates/with-vercel-website/Dockerfile:26
dockerlegacy
templates/with-vercel-postgres/Dockerfile:26
dockerlegacy
templates/with-vercel-mongodb/Dockerfile:26
dockerlegacy
templates/with-postgres/Dockerfile:26
dockerlegacy
templates/website/Dockerfile:26
dockerlegacy
templates/blank/Dockerfile:26
dockerlegacy
templates/_template/Dockerfile:26
dockerlegacy
examples/remix/website/Dockerfile:9
dockerlegacy
examples/remix/payload/Dockerfile:25
dockerlegacy
examples/localization/Dockerfile:8
dockerlegacy
examples/astro/payload/Dockerfile:25
dockerlegacy
packages/drizzle/src/utilities/createSchemaGenerator.ts:345
owaspeval_used
tools/scripts/src/license-check.ts:67
owaspexec_used
tools/scripts/src/pack-all-to-dest.ts:80
owaspexec_used
templates/with-vercel-website/src/utilities/getMediaUrl.ts:7
qualitylegacy
templates/with-vercel-website/src/endpoints/seed/index.ts:43
qualitylegacy
templates/website/src/utilities/getMediaUrl.ts:7
qualitylegacy
templates/website/src/endpoints/seed/index.ts:43
qualitylegacy
templates/ecommerce/src/endpoints/seed/index.ts:87
qualitylegacy
packages/plugin-mcp/src/index.ts:93
qualitylegacy
packages/plugin-mcp/src/index.ts:92
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:197
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:161
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:159
qualitylegacy
packages/plugin-ecommerce/src/types/index.ts:137
qualitylegacy
packages/plugin-ecommerce/src/collections/carts/endpoints/updateItem.ts:40
qualitylegacy
packages/plugin-ecommerce/src/collections/carts/endpoints/updateItem.ts:34
qualitylegacy
packages/plugin-ecommerce/src/collections/carts/endpoints/updateItem.ts:28
qualitylegacy
packages/payload/src/config/types.ts:239
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/836245fa-286f-4238-953c-95e0eac60349/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/836245fa-286f-4238-953c-95e0eac60349/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.