https://github.com/facebook/lexical
· scanned 2026-05-16 12:50 UTC (1 day, 8 hours ago)
· 10 languages
243 findings (40 legacy + 203 scanner) 16th percentile · Typescript · large (100-500K LoC) Scanner says 77 (lower by 14)
Last scanned 3 days, 1 hour ago · v1 · 236 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
87.4 | 0.25 | 21.85 |
testing_score |
31.0 | 0.20 | 6.20 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
55.0 | 0.15 | 8.25 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 62.3 |
web: 1.6 ·
threat: 11.0
Showing 15 of 236 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/lexical-playground/src/plugins/AutoEmbedPlugin/index.tsx:180
injectionlegacy
packages/lexical-markdown/src/MarkdownTransformers.ts:229
redoslegacy
.well-known/security.txt
qualitylegacy
.github/workflows/call-increment-version.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/version.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/call-post-release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/nightly-release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/pre-release.yml
supply-chaingithub-actionsleast-privilege
flow-typed/environments/jsx.js:857
owaspdangerous_innerhtml
packages/lexical-playground/src/nodes/ExcalidrawNode/ExcalidrawImage.tsx:134
owaspdangerous_innerhtml
This page is publicly accessible at:
https://repobility.com/scan/8d1686ea-db53-4e16-8725-bca7bae2d515/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8d1686ea-db53-4e16-8725-bca7bae2d515/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.