Scan timing: clone 4.95s · analysis 5.68s · 8.0 MB · GitHub API rate-limit (preflight)
https://github.com/nginx/nginx
· scanned 2026-05-20 15:23 UTC (2 weeks, 1 day ago)
· 10 languages
59 findings (47 legacy + 12 scanner) Scanner says 93 (lower by 36)
Last scanned 2 weeks, 1 day ago · v2 · 53 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
90.0 | 0.25 | 22.50 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
69.0 | 0.15 | 10.35 |
code_quality |
30.7 | 0.10 | 3.07 |
| Overall | 1.00 | 56.9 |
Showing 41 of 53 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/mail/ngx_mail_imap_module.c:31
qualitylegacy
src/http/modules/ngx_http_secure_link_module.c:16
qualitylegacy
src/core/ngx_crypt.c:58
qualitylegacy
src/http/ngx_http_cache.h:193
path_traversallegacy
.github/workflows/buildbot.yml:11
dependencylegacy
.github/workflows/check-pr.yml:8
dependencylegacy
.github/workflows/check-pr.yml:8
supply-chaingithub-actionspinned-dependencies
.github/workflows/buildbot.yml:11
supply-chaingithub-actionspinned-dependencies
.github/workflows/set-creation-date.yaml
supply-chaingithub-actionsleast-privilege
src/http/modules/ngx_http_tunnel_module.c:270
qualitylegacy
src/http/modules/ngx_http_try_files_module.c:141
qualitylegacy
src/http/modules/ngx_http_sub_filter_module.c:102
qualitylegacy
src/http/modules/ngx_http_static_module.c:144
qualitylegacy
src/http/modules/ngx_http_static_module.c:55
qualitylegacy
src/http/modules/ngx_http_split_clients_module.c:90
qualitylegacy
src/http/modules/ngx_http_range_filter_module.c:64
qualitylegacy
src/http/modules/ngx_http_range_filter_module.c:63
qualitylegacy
src/http/modules/ngx_http_random_index_module.c:76
qualitylegacy
src/http/modules/ngx_http_not_modified_filter_module.c:19
qualitylegacy
src/http/modules/ngx_http_limit_req_module.c:483
qualitylegacy
src/http/modules/ngx_http_limit_req_module.c:268
qualitylegacy
src/http/modules/ngx_http_limit_req_module.c:267
qualitylegacy
src/http/modules/ngx_http_limit_conn_module.c:231
qualitylegacy
src/http/modules/ngx_http_headers_filter_module.c:127
qualitylegacy
src/http/modules/ngx_http_gzip_static_module.c:90
qualitylegacy
src/http/modules/ngx_http_gzip_filter_module.c:528
qualitylegacy
src/http/modules/ngx_http_gunzip_filter_module.c:68
qualitylegacy
src/http/modules/ngx_http_chunked_filter_module.c:22
qualitylegacy
src/event/quic/ngx_event_quic_udp.c:24
qualitylegacy
src/event/quic/ngx_event_quic_udp.c:9
qualitylegacy
src/event/ngx_event_udp.c:271
qualitylegacy
src/event/ngx_event_udp.c:26
qualitylegacy
src/event/ngx_event_acceptex.c:141
qualitylegacy
src/event/modules/ngx_win32_select_module.c:41
qualitylegacy
src/event/modules/ngx_win32_select_module.c:1
qualitylegacy
src/event/modules/ngx_win32_poll_module.c:12
qualitylegacy
src/event/modules/ngx_select_module.c:39
qualitylegacy
src/event/modules/ngx_epoll_module.c:498
qualitylegacy
src/core/ngx_sha1.c:15
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/9f08cd24-08f7-4a0a-8ed3-f69967e24690/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9f08cd24-08f7-4a0a-8ed3-f69967e24690/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.