Scan timing: clone 4.16s · analysis 9.54s · 7.1 MB · GitHub API rate-limit (preflight)
https://github.com/ohmyzsh/ohmyzsh
· scanned 2026-06-05 04:33 UTC (5 hours, 28 minutes ago)
· 10 languages
67 findings (29 legacy + 38 scanner) 75th percentile · Python · tiny (<2K LoC) Scanner says 75 (lower by 4)
Last scanned 5 hours, 28 minutes ago · v2 · 48 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
55.0 | 0.25 | 13.75 |
testing_score |
70.0 | 0.20 | 14.00 |
documentation_score |
93.0 | 0.15 | 13.95 |
practices_score |
81.0 | 0.15 | 12.15 |
code_quality |
73.7 | 0.10 | 7.37 |
| Overall | 1.00 | 71.0 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
.github/workflows/dependencies/updater.py:294
plugins/shell-proxy/proxy.py:17
plugins/aliases/termcolor.py:86
plugins/aliases/cheatsheet.py:50
plugins/pip/pip.plugin.zsh:121
plugins/git-prompt/gitstatus.py:63
plugins/emoji/update_emoji.py:7
plugins/sprunge/sprunge.plugin.zsh:6
plugins/frontend-search/frontend-search.plugin.zsh:58
plugins/drush/drush.plugin.zsh:36
plugins/tmux/tmux.plugin.zsh:182
plugins/shell-proxy/proxy.py:42
This page is publicly accessible at:
https://repobility.com/scan/b387ada8-9962-4839-a2be-d5dbb09d4cdd/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b387ada8-9962-4839-a2be-d5dbb09d4cdd/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.