Scan timing: clone 4.16s · analysis 9.54s · 7.1 MB · GitHub API rate-limit (preflight)
https://github.com/ohmyzsh/ohmyzsh
· scanned 2026-06-05 04:33 UTC (4 hours, 18 minutes ago)
· 10 languages
67 findings (29 legacy + 38 scanner) 75th percentile · Python · tiny (<2K LoC) Scanner says 75 (lower by 4)
Last scanned 4 hours, 18 minutes ago · v2 · 48 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
55.0 | 0.25 | 13.75 |
testing_score |
70.0 | 0.20 | 14.00 |
documentation_score |
93.0 | 0.15 | 13.95 |
practices_score |
81.0 | 0.15 | 12.15 |
code_quality |
73.7 | 0.10 | 7.37 |
| Overall | 1.00 | 71.0 |
Showing 37 of 48 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
plugins/drush/drush.plugin.zsh:64
qualitylegacy
plugins/macos/spotify:57
credential_exposurelegacy
plugins/dotenv/README.md:29
credential_exposurelegacy
plugins/dotenv/README.md:21
credential_exposurelegacy
plugins/dotenv/README.md:20
credential_exposurelegacy
plugins/genpass/genpass-apple:8
credential_exposurelegacy
plugins/drush/drush.plugin.zsh:59
secrets
plugins/wp-cli/wp-cli.plugin.zsh:99
secrets
plugins/tmux/tmux.plugin.zsh:182
qualitylegacy
.github/workflows/dependencies/updater.py:231
qualitylegacy
.github/workflows/dependencies/updater.py:235
qualitylegacy
.github/workflows/dependencies/updater.py:67
qualitylegacy
.github/workflows/dependencies/updater.py:64
qualitylegacy
.github/workflows/dependencies/updater.py:68
qualitylegacy
.github/workflows/dependencies/updater.py:67
qualitylegacy
.github/workflows/dependencies/updater.py:294
qualitylegacy
plugins/wd/README.md:88
dependencylegacy
plugins/mise/README.md:12
dependencylegacy
plugins/azure/README.md:48
dependencylegacy
.github/workflows/dependencies.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/scorecard.yml
supply-chaingithub-actionsleast-privilege
plugins/battery/battery.plugin.zsh
securityports
.github/workflows/dependencies/requirements.txt:1
dependencylegacy
.github/workflows/dependencies/requirements.txt:3
dependencylegacy
plugins/shell-proxy/proxy.py:61
dead-code
plugins/shell-proxy/proxy.py:57
dead-code
.github/workflows/dependencies/updater.py:72
dead-code
plugins/sprunge/sprunge.plugin.zsh:6
qualitylegacy
plugins/frontend-search/frontend-search.plugin.zsh:58
qualitylegacy
plugins/drush/drush.plugin.zsh:36
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/b387ada8-9962-4839-a2be-d5dbb09d4cdd/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b387ada8-9962-4839-a2be-d5dbb09d4cdd/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.