https://github.com/payloadcms/payload
· scanned 2026-05-16 13:37 UTC (3 weeks, 3 days ago)
· 10 languages
1367 raw signals (172 security + 1195 graph) 8/10 scanners ran 2nd percentile · Typescript · huge (>500K LoC)
Last scanned 3 weeks, 5 days ago · v1 · 42 actionable findings from 1 signal source. 128 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
23.7 | 0.25 | 5.92 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
74.0 | 0.15 | 11.10 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 68.0 |
web: 3.0 ·
authz: 10.6 ·
docker: 140.4 ·
threat: 12.8 ·
journey: 44.4
Showing 36 of 42 actionable findings. 170 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
templates/with-postgres/docker-compose.yml:19templates/with-vercel-website/docker-compose.yml:3test/docker-compose.yml:116test/docker-compose.yml:19, 52, 83, 145 (4 hits)examples/astro/payload/docker-compose.yml:19examples/localization/docker-compose.yml:17examples/remix/payload/docker-compose.yml:19templates/_template/docker-compose.yml:19templates/blank/docker-compose.yml:19templates/website/docker-compose.yml:17templates/with-postgres/docker-compose.yml:19examples/astro/payload/Dockerfile:25examples/localization/Dockerfile:8examples/remix/payload/Dockerfile:25examples/remix/website/Dockerfile:9templates/_template/Dockerfile:26templates/blank/Dockerfile:26templates/website/Dockerfile:26templates/with-postgres/Dockerfile:26templates/with-vercel-website/src/app/(frontend)/(sitemaps)/pages-sitemap.xml/route.ts:64
templates/website/src/app/(frontend)/(sitemaps)/pages-sitemap.xml/route.ts:64
templates/with-vercel-website/src/app/(frontend)/(sitemaps)/posts-sitemap.xml/route.ts:51
templates/website/src/app/(frontend)/(sitemaps)/posts-sitemap.xml/route.ts:51
templates/with-vercel-website/src/app/(frontend)/next/exit-preview/route.ts:3
templates/website/src/app/(frontend)/next/exit-preview/route.ts:3
templates/with-vercel-website/src/app/(frontend)/next/preview/route.ts:15
templates/website/src/app/(frontend)/next/preview/route.ts:15
templates/with-vercel-website/src/app/(frontend)/next/seed/route.ts:8
templates/website/src/app/(frontend)/next/seed/route.ts:8
templates/ecommerce/src/app/(app)/(account)/orders/page.tsx:38
test/docker-compose.yml:19, 52, 116, 145, 184, 221 (6 hits)examples/astro/payload/docker-compose.yml:19examples/localization/docker-compose.yml:17examples/remix/payload/docker-compose.yml:19templates/_template/docker-compose.yml:19templates/blank/docker-compose.yml:19templates/website/docker-compose.yml:17templates/with-postgres/docker-compose.yml:19.dockerignore
CI/CD securitycontainers
examples/astro/payload/docker-compose.yml:19examples/localization/docker-compose.yml:17examples/remix/payload/docker-compose.yml:19templates/_template/docker-compose.yml:19templates/blank/docker-compose.yml:19templates/website/docker-compose.yml:17templates/with-postgres/docker-compose.yml:19templates/with-vercel-mongodb/docker-compose.yml:19.dockerignore
CI/CD securitycontainers
examples/remix/website/Dockerfile:20
CI/CD securitycontainers
examples/localization/Dockerfile:12
CI/CD securitycontainers
examples/remix/website/Dockerfile:17
CI/CD securitycontainers
examples/localization/Dockerfile:9
CI/CD securitycontainers
packages/plugin-ecommerce/src/types/index.ts:137, 159, 161, 197 (4 hits)packages/plugin-ecommerce/src/collections/carts/endpoints/updateItem.ts:28, 34, 40 (3 hits)packages/plugin-mcp/src/index.ts:92, 93 (2 hits)packages/payload/src/config/types.ts:239templates/ecommerce/src/endpoints/seed/index.ts:87templates/website/src/endpoints/seed/index.ts:43templates/website/src/utilities/getMediaUrl.ts:7templates/with-vercel-website/src/endpoints/seed/index.ts:43index.html
.well-known/security.txt
examples/astro/payload/docker-compose.yml:3examples/localization/docker-compose.yml:3examples/remix/payload/docker-compose.yml:3templates/_template/docker-compose.yml:3templates/blank/docker-compose.yml:3templates/website/docker-compose.yml:3templates/with-postgres/docker-compose.yml:3templates/with-vercel-mongodb/docker-compose.yml:3test/docker-compose.yml:167, 184, 198, 221 (4 hits)examples/astro/payload/docker-compose.yml:3examples/localization/docker-compose.yml:3examples/remix/payload/docker-compose.yml:3templates/_template/docker-compose.yml:3templates/blank/docker-compose.yml:3templates/website/docker-compose.yml:3templates/with-postgres/docker-compose.yml:3test/docker-compose.yml:167, 184, 198, 221 (4 hits)examples/astro/payload/docker-compose.yml:3examples/localization/docker-compose.yml:3examples/remix/payload/docker-compose.yml:3templates/_template/docker-compose.yml:3templates/blank/docker-compose.yml:3templates/website/docker-compose.yml:3templates/with-postgres/docker-compose.yml:3packages/db-vercel-postgres/src/index.ts:3, 11, 159 (3 hits)packages/db-mongodb/src/findVersions.ts:50, 75 (2 hits)packages/db-mongodb/src/updateOne.ts:35, 66 (2 hits)packages/db-sqlite/src/index.ts:1, 10 (2 hits)packages/db-vercel-postgres/src/connect.ts:47, 81 (2 hits).github/actions/activity/src/popular-issues.ts:18packages/codemod/src/transforms/migrate-import-export-hooks/non-matching.output.ts:1packages/db-mongodb/src/countGlobalVersions.ts:21humans.txt
sitemap.xml
.github/actions/activity/pnpm-lock.yaml
packages/db-mongodb/src/predefinedMigrations/migrateVersionsV1_V2.ts:1
packages/db-mongodb/src/predefinedMigrations/migrateRelationshipsV2_V3.ts:1
This page is publicly accessible at:
https://repobility.com/scan/836245fa-286f-4238-953c-95e0eac60349/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/836245fa-286f-4238-953c-95e0eac60349/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.