Scan timing: clone 4.63s · analysis 4.63s · 2.8 MB · GitHub preflight 418ms
https://github.com/headlesshq/headlessmc
· scanned 2026-05-21 20:49 UTC (2 weeks ago)
· 10 languages
154 findings (76 legacy + 78 scanner) 50th percentile · Java · medium (20-100K LoC) Scanner says 80 (lower by 9)
Last scanned 2 weeks ago · v2 · 115 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
78.2 | 0.25 | 19.55 |
testing_score |
80.0 | 0.20 | 16.00 |
documentation_score |
64.0 | 0.15 | 9.60 |
practices_score |
80.0 | 0.15 | 12.00 |
code_quality |
78.7 | 0.10 | 7.87 |
| Overall | 1.00 | 71.0 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
headlessmc-auth/src/main/java/io/github/headlessh…:261
headlessmc-api/src/main/java/io/github/headlesshq…:39
headlessmc-api/src/main/java/io/github/headlesshq…:46
headlessmc-launcher/src/main/java/io/github/headl…:29
headlessmc-launcher/src/main/java/io/github/headl…:43
headlessmc-scripts/version.py:9
headlessmc-lwjgl/src/main/java/io/github/headless…:47
headlessmc-lwjgl/src/main/java/io/github/headless…:46
headlessmc-launcher-wrapper/src/main/java/io/gith…:72
headlessmc-launcher/src/main/java/io/github/headl…:281
headlessmc-launcher-wrapper/src/main/java/io/gith…:34
headlessmc-graalvm/src/main/java/io/github/headle…:89
This page is publicly accessible at:
https://repobility.com/scan/aacccc06-97b5-40f6-a398-8d90565325f3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/aacccc06-97b5-40f6-a398-8d90565325f3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.