Scan timing: clone 7.27s · analysis 66.33s · 13.0 MB · GitHub API rate-limit (preflight)
https://github.com/Mintplex-Labs/anything-llm
· scanned 2026-06-05 09:32 UTC (5 days, 16 hours ago)
· 10 languages
1480 raw signals (226 security + 1254 graph) 5th percentile · Javascript · large (100-500K LoC) System graph score 49 (higher by 2)
Last scanned 5 days, 16 hours ago · v2 · 620 actionable findings from 2 signal sources. 233 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
41.5 | 0.25 | 10.38 |
testing_score |
20.0 | 0.20 | 4.00 |
documentation_score |
75.6 | 0.15 | 11.34 |
practices_score |
83.0 | 0.15 | 12.45 |
code_quality |
43.4 | 0.10 | 4.34 |
| Overall | 1.00 | 51.5 |
Showing 528 of 620 actionable findings. 853 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
server/endpoints/admin.js:543
server/endpoints/admin.js:208
server/endpoints/admin.js:129
server/endpoints/admin.js:295
server/endpoints/api/admin/index.js:374
server/endpoints/api/admin/index.js:215
server/endpoints/utils/outlookAgentUtils.js:21
server/endpoints/utils/outlookAgentUtils.js:172
server/endpoints/admin.js:519
server/endpoints/admin.js:176
server/endpoints/admin.js:462
server/endpoints/admin.js:88
server/endpoints/admin.js:52
server/endpoints/admin.js:276
server/endpoints/admin.js:257
server/endpoints/api/admin/index.js:316
server/endpoints/api/admin/index.js:718
server/endpoints/api/admin/index.js:143
server/endpoints/api/admin/index.js:85
server/endpoints/api/admin/index.js:662
server/endpoints/api/admin/index.js:480
server/endpoints/api/admin/index.js:547
server/utils/vectorDbProviders/pinecone/PINECONE_SETUP.md:22
frontend/public/embed/anythingllm-chat-widget.min.js:37
.github/workflows/cleanup-qa-tag.yaml:23, 61 (2 hits)frontend/src/components/VectorDBSelection/ChromaDBOptions/index.jsx:45
frontend/src/locales/ar/common.js:19, 20, 24, 1256, 1475 (5 hits)frontend/src/locales/ca/common.js:19, 20, 25, 1114, 1482 (5 hits)frontend/src/locales/cs/common.js:19, 20, 25, 1029, 1391 (5 hits)frontend/src/locales/da/common.js:19, 20, 25, 1271, 1498 (5 hits)frontend/src/locales/de/common.js:19, 20, 25, 1389, 1526 (5 hits)frontend/src/locales/en/common.js:18, 19, 24, 1254, 1616 (5 hits)frontend/src/locales/es/common.js:19, 20, 25, 1404, 1541 (5 hits)frontend/src/locales/et/common.js:19, 20, 25, 1329, 1453 (5 hits)frontend/src/locales/fa/common.js:35, 36, 41, 1263, 1487 (5 hits)frontend/src/locales/fr/common.js:33, 34, 39, 1297, 1519 (5 hits)frontend/src/locales/he/common.js:19, 20, 24, 1317, 1442 (5 hits)frontend/src/locales/it/common.js:34, 35, 40, 1302, 1541 (5 hits)frontend/src/locales/ja/common.js:19, 20, 25, 1253, 1489 (5 hits)frontend/src/locales/ko/common.js:19, 20, 24, 1331, 1460 (5 hits)frontend/src/locales/lt/common.js:19, 20, 25, 1030, 1395 (5 hits)frontend/src/locales/lv/common.js:19, 20, 24, 1374, 1508 (5 hits)frontend/src/locales/nl/common.js:34, 35, 40, 1281, 1512 (5 hits)frontend/src/locales/pl/common.js:19, 20, 25, 1382, 1516 (5 hits)frontend/src/locales/pt_BR/common.js:19, 20, 25, 1363, 1489 (5 hits)frontend/src/locales/ro/common.js:19, 20, 25, 649, 1517 (5 hits)frontend/src/locales/ru/common.js:19, 20, 25, 1291, 1525 (5 hits)frontend/src/locales/tr/common.js:34, 35, 40, 1284, 1510 (5 hits)frontend/src/locales/vn/common.js:34, 35, 40, 1267, 1495 (5 hits)frontend/src/locales/zh/common.js:20, 24, 1399 (3 hits)frontend/src/locales/zh_TW/common.js:20, 24, 1394 (3 hits)server/endpoints/api/admin/index.js:96, 160 (2 hits)server/endpoints/system.js:428
docker/docker-compose.yml:7
CI/CD securitycontainers
cloud-deployments/huggingface-spaces/Dockerfile:21cloud-deployments/openshift/Dockerfile:14docker/Dockerfile:2cloud-deployments/openshift/Dockerfile:27, 105 (2 hits)docker/Dockerfile:15, 84 (2 hits)server/endpoints/embedManagement.js:73
server/endpoints/embedManagement.js:115
server/endpoints/workspacesParsedFiles.js:46
server/endpoints/agentSkillWhitelist.js:48
server/endpoints/document.js:14
server/endpoints/document.js:44
server/endpoints/embedManagement.js:93
server/endpoints/embedManagement.js:55
server/endpoints/embedManagement.js:34
collector/extensions/index.js:36
collector/extensions/index.js:66
collector/extensions/index.js:142
collector/extensions/index.js:168
collector/extensions/index.js:196
collector/extensions/index.js:216
collector/extensions/index.js:15
collector/extensions/index.js:123
collector/extensions/index.js:96
server/endpoints/invite.js:37
collector/index.js:75
collector/index.js:45
collector/index.js:109
collector/index.js:179
collector/index.js:154
collector/index.js:134
.github/workflows/lint.yaml:25, 28, 33, 41, 49 (10 hits).github/workflows/run-tests.yaml:20, 23, 28, 38, 48 (10 hits).github/workflows/check-package-versions.yaml:23, 26 (4 hits).github/workflows/check-translations.yaml:23, 26 (4 hits).github/workflows/build-and-push-image-semver.yaml:20 (2 hits).github/workflows/build-and-push-image.yaml:39 (2 hits).github/workflows/build-qa-tag.yaml:40 (2 hits).github/workflows/sponsors.yaml:14 (2 hits)collector/package.json:1
frontend/src/components/TextToSpeech/OpenAiOptions/index.jsx:16frontend/src/pages/Admin/Agents/GMailSkillPanel/index.jsx:278frontend/src/pages/Admin/Agents/GoogleCalendarSkillPanel/index.jsx:287frontend/src/pages/Admin/Agents/SQLConnectorSelection/SQLConnectionModal.jsx:360frontend/src/EmbeddingProgressContext.jsx:195frontend/src/components/WorkspaceChat/ChatContainer/PromptInput/SpeechToText/useSilenceDetector.js:66frontend/src/pages/Admin/Agents/CreateFileSkillPanel/index.jsx:82frontend/src/components/Modals/Password/MultiUserAuth.jsx:209, 228, 237, 261 (4 hits)frontend/src/AuthContext.jsx:15, 32 (2 hits)frontend/src/components/Modals/Password/SingleUserAuth.jsx:40, 56 (2 hits)frontend/src/components/Modals/Password/index.jsx:51, 93 (2 hits)frontend/src/components/PrivateRoute/index.jsx:41, 54 (2 hits)docker/Dockerfile:167
CI/CD securitycontainers
frontend/src/hooks/usePromptInputStorage.js:37
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
package.json
package.json
index.html
.well-known/security.txt
.github/workflows/build-and-push-image.yaml:125
.github/workflows/build-and-push-image-semver.yaml:104
frontend/public/robots.txt
docker/Dockerfile:131
containersPinned dependencies
cloud-deployments/openshift/Dockerfile:161
containersPinned dependencies
.github/workflows/sponsors.yaml:18, 27, 34 (6 hits).github/workflows/build-qa-tag.yaml:43, 48, 58 (3 hits).github/workflows/build-and-push-image-semver.yaml:36, 67 (2 hits).github/workflows/build-and-push-image.yaml:55, 88 (2 hits).github/workflows/build-and-push-image-semver.yaml.github/workflows/build-and-push-image.yaml.github/workflows/build-qa-tag.yaml.github/workflows/cleanup-qa-tag.yaml.github/workflows/sponsors.yamlfrontend/src/components/ChatBubble/index.jsx:23
Dangerous innerhtml
frontend/src/components/Modals/ManageWorkspace/DataConnectors/Connectors/Github/index.jsx:252
Dangerous innerhtml
frontend/src/components/Modals/ManageWorkspace/DataConnectors/Connectors/Gitlab/index.jsx:280
Dangerous innerhtml
frontend/src/components/Modals/ManageWorkspace/Documents/WorkspaceDirectory/index.jsx:343
Dangerous innerhtml
frontend/src/components/WorkspaceChat/ChatContainer/ChatHistory/Chartable/index.jsx:397
Dangerous innerhtml
frontend/src/components/WorkspaceChat/ChatContainer/ChatHistory/HistoricalMessage/index.jsx:308
Dangerous innerhtml
frontend/src/components/WorkspaceChat/ChatContainer/ChatHistory/PromptReply/index.jsx:100
Dangerous innerhtml
frontend/src/components/WorkspaceChat/ChatContainer/ChatHistory/ThoughtContainer/index.jsx:203
Dangerous innerhtml
frontend/src/pages/GeneralSettings/ChatEmbedWidgets/EmbedChats/MarkdownRenderer.jsx:82
Dangerous innerhtml
frontend/src/pages/GeneralSettings/ChatEmbedWidgets/EmbedConfigs/EmbedRow/CodeSnippetModal/index.jsx:108
Dangerous innerhtml
frontend/src/pages/GeneralSettings/Chats/MarkdownRenderer.jsx:82
Dangerous innerhtml
frontend/src/pages/GeneralSettings/CommunityHub/ImportItem/Steps/PullAndReview/HubItem/AgentSkill.jsx:175
Dangerous innerhtml
frontend/src/pages/GeneralSettings/ScheduledJobs/RunDetailPage.jsx:377
Dangerous innerhtml
cloud-deployments/helm/charts/anythingllm/values.yaml
Ports
.dockerignore
CI/CD securitycontainers
docker/docker-compose.yml:7
CI/CD securitycontainers
frontend/src/components/EmbeddingSelection/LocalAiOptions/index.jsx:71, 109, 150, 197, 235 (5 hits)collector/processSingleFile/convert/asImage.js:19, 36, 37 (3 hits)collector/processSingleFile/convert/asTxt.js:21, 39, 40 (3 hits)frontend/src/components/EmbeddingSelection/LiteLLMOptions/index.jsx:35, 137, 147 (3 hits)collector/processSingleFile/convert/asEPub.js:41, 42 (2 hits)collector/processSingleFile/convert/asOfficeMime.js:24, 40 (2 hits)collector/processSingleFile/convert/asPDF/index.js:42, 63 (2 hits)frontend/src/components/CommunityHub/PublishEntityModal/SystemPrompts/index.jsx:9, 38 (2 hits)server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
server/package.json
llms.txt
humans.txt
sitemap.xml
frontend/public/robots.txt
server/utils/agents/aibitat/plugins/gmail/drafts/gmail-create-draft.js:1server/utils/agents/aibitat/plugins/gmail/drafts/gmail-delete-draft.js:1server/utils/agents/aibitat/plugins/gmail/drafts/gmail-get-draft.js:1server/utils/agents/aibitat/plugins/gmail/drafts/gmail-send-draft.js:1server/utils/agents/aibitat/plugins/gmail/drafts/gmail-update-draft.js:1server/utils/agents/aibitat/plugins/outlook/drafts/outlook-create-draft.js:1server/utils/agents/aibitat/plugins/outlook/drafts/outlook-delete-draft.js:1server/utils/agents/aibitat/plugins/outlook/drafts/outlook-send-draft.js:1cloud-deployments/huggingface-spaces/Dockerfile:21
containersPinned dependencies
docker/Dockerfile:141
containersPinned dependencies
cloud-deployments/openshift/Dockerfile:171
containersPinned dependencies
docker/Dockerfile:2
containersPinned dependencies
cloud-deployments/openshift/Dockerfile:14
containersPinned dependencies
Showing first 300 of 528. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/a5807e42-6406-442b-ac11-bda151585a66/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a5807e42-6406-442b-ac11-bda151585a66/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.