https://github.com/facebook/lexical
· scanned 2026-05-16 12:50 UTC (1 day, 7 hours ago)
· 10 languages
243 findings (40 legacy + 203 scanner) 16th percentile · Typescript · large (100-500K LoC) Scanner says 77 (lower by 14)
Last scanned 3 days, 1 hour ago · v1 · 236 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
87.4 | 0.25 | 21.85 |
testing_score |
31.0 | 0.20 | 6.20 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
55.0 | 0.15 | 8.25 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 62.3 |
web: 1.6 ·
threat: 11.0
Showing 233 of 236 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
examples/vanilla-js/src/main.ts:18
injectionlegacy
examples/vanilla-js-plugin/src/main.ts:20
injectionlegacy
packages/lexical-playground/src/plugins/ActionsPlugin/index.tsx:168
xxelegacy
packages/lexical-clipboard/src/clipboard.ts:179
xxelegacy
packages/lexical-react/src/LexicalAutoEmbedPlugin.tsx:177
ssrflegacy
packages/lexical-utils/src/index.ts:151
ssrflegacy
scripts/update-tsconfig.mjs:112
ssrflegacy
packages/lexical-playground/src/plugins/AutoEmbedPlugin/index.tsx:180
injectionlegacy
packages/lexical-markdown/src/MarkdownTransformers.ts:229
redoslegacy
.well-known/security.txt
qualitylegacy
.github/workflows/call-increment-version.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/version.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/call-post-release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/nightly-release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/pre-release.yml
supply-chaingithub-actionsleast-privilege
flow-typed/environments/jsx.js:857
owaspdangerous_innerhtml
packages/lexical-playground/src/nodes/ExcalidrawNode/ExcalidrawImage.tsx:134
owaspdangerous_innerhtml
packages/lexical/src/extension-core/index.ts:23
qualitylegacy
packages/lexical/src/LexicalEditorState.ts:47
qualitylegacy
packages/lexical-react/src/shared/LexicalMenu.tsx:237
qualitylegacy
packages/lexical-react/src/shared/LexicalMenu.tsx:127
qualitylegacy
packages/lexical-react/src/LexicalRichTextPlugin.tsx:11
qualitylegacy
packages/lexical-react/src/LexicalMarkdownShortcutPlugin.tsx:12
qualitylegacy
packages/lexical-react/src/LexicalHorizontalRulePlugin.ts:17
qualitylegacy
packages/lexical-react/src/LexicalHorizontalRuleNode.tsx:65
qualitylegacy
packages/lexical-react/src/LexicalHorizontalRuleNode.tsx:39
qualitylegacy
packages/lexical-react/src/LexicalBlockWithAlignableContents.tsx:74
qualitylegacy
packages/lexical-playground/src/utils/setFloatingElemPositionForLinkEditor.ts:7
qualitylegacy
packages/lexical-playground/src/plugins/PageBreakExtension/index.tsx:2
qualitylegacy
packages/lexical-playground/src/plugins/DraggableBlockPlugin/index.tsx:53
qualitylegacy
packages/lexical-playground/src/nodes/YouTubeNode.tsx:5
qualitylegacy
packages/lexical-playground/src/nodes/YouTubeNode.tsx:1
qualitylegacy
packages/lexical-playground/src/nodes/TweetNode.tsx:5
qualitylegacy
packages/lexical-playground/src/nodes/PollComponent.tsx:139
qualitylegacy
packages/lexical-playground/src/nodes/ImageNode.tsx:297
qualitylegacy
packages/lexical-code-shiki/src/CodeHighlighterShiki.ts:1
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
examples/extension-sveltekit-ssr-hydration/static/robots.txt
qualitylegacy
package.json
supply-chainnpminstall-scripts
packages/lexical-devtools/package.json
supply-chainnpminstall-scripts
examples/extension-sveltekit-ssr-hydration/package.json
supply-chainnpminstall-scripts
This page is publicly accessible at:
https://repobility.com/scan/8d1686ea-db53-4e16-8725-bca7bae2d515/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8d1686ea-db53-4e16-8725-bca7bae2d515/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.