Scan timing: clone 2.76s · analysis 8.11s · 0.7 MB · GitHub API rate-limit (preflight)
https://github.com/expressjs/express
· scanned 2026-06-05 08:36 UTC (5 days, 19 hours ago)
· 10 languages
332 raw signals (80 security + 252 graph) 61st percentile · Javascript · medium (20-100K LoC) System graph score 65 (higher by 12)
Last scanned 5 days, 19 hours ago · v2 · 164 actionable findings from 2 signal sources. 42 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
69.5 | 0.25 | 17.38 |
testing_score |
87.0 | 0.20 | 17.40 |
documentation_score |
63.0 | 0.15 | 9.45 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
74.8 | 0.10 | 7.48 |
| Overall | 1.00 | 77.1 |
Showing 141 of 164 actionable findings. 206 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
lib/response.js:355
examples/route-middleware/index.js:82
test/express.json.js:62, 79, 536, 735 (4 hits)test/express.raw.js:33, 71, 361, 504 (4 hits)test/express.text.js:32, 66, 393, 561 (4 hits)test/express.urlencoded.js:33, 68, 639, 817 (4 hits)test/app.options.js:10test/acceptance/web-service.js:10, 18, 26, 37, 45, 53, 66, 74, +3 more (11 hits)test/acceptance/multi-router.js:16, 24, 32, 40 (4 hits)package.json
package.json
package.json
package.json
package.json
package.json
package.json
package.json
.github/workflows/scorecard.yml
CI/CD securitySupply chainGithub actions
test/express.urlencoded.js:433, 461, 554 (3 hits)test/express.text.js:237, 239 (2 hits)test/express.raw.js:222test/res.jsonp.js:234test/res.sendFile.js:258package.json
package.json
package.json
package.json
package.json
This page is publicly accessible at:
https://repobility.com/scan/85f8264f-a2a1-4cfa-a7bb-94025c9f6b26/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/85f8264f-a2a1-4cfa-a7bb-94025c9f6b26/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.