Scan timing: clone 3.85s · analysis 8.78s · 39.2 MB · GitHub API rate-limit (preflight)
https://github.com/webpack/webpack
· scanned 2026-06-05 08:57 UTC (5 days, 18 hours ago)
· 10 languages
1079 raw signals (87 security + 992 graph) 11/13 scanners ran 100th percentile · Javascript · huge (>500K LoC) System graph score 64 (higher by 29)
Last scanned 5 days, 18 hours ago · v2 · 514 actionable findings from 2 signal sources. 69 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
89.0 | 0.15 | 13.35 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 93.2 |
Showing 317 of 514 actionable findings. 583 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/test.yml:168, 219, 341 (3 hits).github/workflows/benchmarks.yml:99lib/JavascriptMetaInfoPlugin.js:42
Eval used
lib/DefinePlugin.js:83
Exec used
setup/setup.js:37
Exec used
types.d.ts:22431
Exec used
index.html
.well-known/security.txt
.github/workflows/benchmarks.yml.github/workflows/dependabot.yml.github/workflows/examples.yml.github/workflows/release.yml.github/workflows/test.ymlexamples/custom-json-modules/data.yaml
Ports
lib/ExportsInfoApiPlugin.js:46, 48, 49 (3 hits)lib/ConstPlugin.js:320, 321 (2 hits)lib/JavascriptMetaInfoPlugin.js:40, 42 (2 hits)lib/UseStrictPlugin.js:35, 37 (2 hits)lib/dependencies/ImportDependency.js:21, 44 (2 hits)hot/only-dev-server.js:91lib/CompatibilityPlugin.js:170lib/EvalSourceMapDevToolPlugin.js:173llms.txt
humans.txt
robots.txt
sitemap.xml
package.json
CI/CD securitySupply chainNpm
Showing first 300 of 317. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/aca40d56-d526-49b3-b7c4-a68c7a21b443/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/aca40d56-d526-49b3-b7c4-a68c7a21b443/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.