https://github.com/excalidraw/excalidraw
· scanned 2026-06-05 05:07 UTC (3 hours, 56 minutes ago)
· 10 languages
408 findings (70 legacy + 338 scanner) 11/13 scanners ran 79th percentile · Typescript · large (100-500K LoC) Scanner says 71 (higher by 12)
Last scanned 3 hours, 56 minutes ago · v2 · 239 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
77.0 | 0.20 | 15.40 |
documentation_score |
77.0 | 0.15 | 11.55 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 83.0 |
Showing 134 of 239 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
dev-docs/docusaurus.config.js:139
secrets
packages/common/src/constants.ts:468
secrets
examples/with-script-in-browser/.codesandbox/Dockerfile:1
dependencylegacy
.codesandbox/Dockerfile:1
dependencylegacy
packages/element/src/image.ts:105
xxelegacy
packages/excalidraw/mermaid.ts:28
xsslegacy
packages/excalidraw/fonts/ExcalidrawFontFace.ts:21
xsslegacy
packages/excalidraw/charts/charts.radar.ts:53
xsslegacy
packages/excalidraw/charts/charts.parse.ts:8
qualitylegacy
scripts/buildDocs.js:4
owaspexec_used
scripts/updateChangelog.js:28
owaspexec_used
packages/excalidraw/components/TTDDialog/Chat/ChatMessage.tsx:86
securitylegacy
excalidraw-app/components/TopErrorBoundary.tsx:68
securitylegacy
excalidraw-app/components/ExportToExcalidrawPlus.tsx:83
securitylegacy
examples/with-script-in-browser/.codesandbox/Dockerfile:1
dockerlegacy
Dockerfile:16
dockerlegacy
.codesandbox/Dockerfile:1
dockerlegacy
Dockerfile:5
dockerlegacy
packages/common/src/editorInterface.ts:208
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
.github/workflows/sentry-production.yml:25
dependencylegacy
public/robots.txt
qualitylegacy
excalidraw-app/share/QRCode.tsx:53
owaspdangerous_innerhtml
Dockerfile
securityports
.dockerignore
dockerlegacy
docker-compose.yml:1
dockerlegacy
docker-compose.yml:1
dockerlegacy
examples/with-script-in-browser/.codesandbox/Dockerfile:5
dockerlegacy
.codesandbox/Dockerfile:5
dockerlegacy
examples/with-script-in-browser/.codesandbox/Dockerfile:5
dockerlegacy
.codesandbox/Dockerfile:5
dockerlegacy
packages/excalidraw/components/Stats/MultiDimension.tsx:222
qualitylegacy
packages/excalidraw/components/PenModeButton.tsx:26
qualitylegacy
packages/excalidraw/components/PenModeButton.tsx:23
qualitylegacy
packages/excalidraw/components/MobileMenu.tsx:143
qualitylegacy
packages/excalidraw/components/MagicButton.tsx:18
qualitylegacy
packages/excalidraw/charts/charts.line.ts:6
qualitylegacy
packages/excalidraw/actions/actionDuplicateSelection.tsx:104
qualitylegacy
dev-docs/src/components/Homepage/index.tsx:42
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
package.json
supply-chainnpminstall-scripts
packages/excalidraw/fonts/Excalifont/index.ts:28
qualitylegacy
packages/excalidraw/components/BraveMeasureTextError.tsx:22
qualitylegacy
excalidraw-app/sentry.ts:61
qualitylegacy
excalidraw-app/collab/Portal.tsx:77
qualitylegacy
excalidraw-app/ExcalidrawPlusIframeExport.tsx:187
qualitylegacy
excalidraw-app/components/ExportToExcalidrawPlus.tsx:104
qualitylegacy
excalidraw-app/components/AppSidebar.tsx:35
qualitylegacy
examples/with-script-in-browser/utils.ts:18
qualitylegacy
excalidraw-app/share/QRCode.tsx:53
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/a9bc95b8-738f-4a5d-9d87-5552c27502d9/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a9bc95b8-738f-4a5d-9d87-5552c27502d9/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.