https://github.com/payloadcms/payload
· scanned 2026-05-16 13:37 UTC (1 day, 6 hours ago)
· 10 languages
1367 findings (172 legacy + 1195 scanner) 8/10 scanners ran 17th percentile · Typescript · huge (>500K LoC)
Last scanned 3 days, 3 hours ago · v1 · 1365 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
23.7 | 0.25 | 5.92 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
74.0 | 0.15 | 11.10 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 68.0 |
web: 3.0 ·
authz: 10.6 ·
docker: 140.4 ·
threat: 12.8 ·
journey: 44.4
Showing 245 of 1365 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/db-mongodb/src/predefinedMigrations/migrateVersionsV1_V2.ts:1
qualitylegacy
packages/db-mongodb/src/predefinedMigrations/migrateRelationshipsV2_V3.ts:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/836245fa-286f-4238-953c-95e0eac60349/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/836245fa-286f-4238-953c-95e0eac60349/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.