https://github.com/erxes/erxes
· scanned 2026-05-31 01:22 UTC (1 week, 6 days ago)
· 10 languages
1978 raw signals (93 security + 1885 graph) 11/13 scanners ran 26th percentile · Typescript · medium (20-100K LoC) System graph score 51 (higher by 9)
Last scanned 1 week, 6 days ago · v2 · last Δ -0.2 (diff) · 641 actionable findings from 2 signal sources. 403 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
61.0 | 0.15 | 9.15 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 60.1 |
Showing 390 of 641 actionable findings. 1044 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/ci-api-accounting.yml:61, 62 (2 hits).github/workflows/ci-api-content.yml:61, 62 (2 hits).github/workflows/ci-api-frontline.yml:62, 63 (2 hits).github/workflows/ci-api-gateway.yml:50, 51 (2 hits).github/workflows/ci-api-loyalty.yml:61, 62 (2 hits).github/workflows/ci-api-operation.yml:61, 62 (2 hits).github/workflows/ci-api-payment.yml:61, 62 (2 hits).github/workflows/ci-api-tourism.yml:61, 62 (2 hits)backend/services/automations/src/executions/actions/webhook/outgoing/outgoingWebhook.ts:80
frontend/core-ui/src/modules/types/paths/AppPath.ts:4, 6 (2 hits)frontend/core-ui/src/modules/types/paths/SettingsPath.ts:6
frontend/plugins/mongolian_ui/src/modules/msdynamic/constants.ts:21
package.json:1 (3 hits).github/workflows/ci-api-accounting.yml:25, 33 (4 hits).github/workflows/ci-api-content.yml:25, 33 (4 hits).github/workflows/ci-api-frontline.yml:26, 34 (4 hits).github/workflows/ci-api-loyalty.yml:25, 33 (4 hits).github/workflows/ci-api-payment.yml:25, 33 (4 hits).github/workflows/ci-api-tourism.yml:25, 33 (4 hits).github/workflows/ci-api-operation.yml:25, 33 (3 hits).github/workflows/ci-service-logs.yml:25, 33, 38 (3 hits).github/workflows/ci-api-accounting.yml:28, 52, 55, 59, 66 (6 hits).github/workflows/ci-api-content.yml:28, 52, 55, 59, 66 (6 hits).github/workflows/ci-api-frontline.yml:29, 53, 56, 60, 67 (6 hits).github/workflows/ci-api-loyalty.yml:28, 52, 55, 59, 66 (6 hits).github/workflows/ci-api-payment.yml:28, 52, 55, 59, 66 (6 hits).github/workflows/ci-api-tourism.yml:28, 52, 55, 59, 66 (6 hits).github/workflows/codeql.yml:27, 32, 35 (6 hits).github/workflows/ci-api-core.yml:29, 53, 56, 60, 67 (5 hits)frontend/libs/erxes-ui/src/components/multiselect.tsx:330
Exec used
apps/posclient-front/app/(main)/report/utils/date.ts:28
index.html
.well-known/security.txt
repo-level (3 hits)repo-level (8 hits)repo-level (8 hits)repo-level (4 hits)repo-level (14 hits)repo-level (14 hits)repo-level (5 hits)repo-level (2 hits)repo-level (5 hits)repo-level (3 hits)repo-level (3 hits)repo-level (15 hits)repo-level (2 hits)repo-level (7 hits)repo-level (4 hits)repo-level (12 hits)repo-level (13 hits)repo-level (5 hits)repo-level (2 hits)repo-level (5 hits)repo-level (3 hits)repo-level (9 hits)repo-level (2 hits)repo-level (7 hits)repo-level (7 hits).github/workflows/ci-apps-frontline-widgets.yml.github/workflows/ci-core-ui.yml.github/workflows/ci-ui-accounting.yml.github/workflows/ci-ui-content.yml.github/workflows/ci-ui-frontline.yml.github/workflows/ci-ui-insurance.yml.github/workflows/ci-ui-loyalty.yml.github/workflows/ci-ui-mongolian.ymlapps/frontline-widgets/src/app/form/components/ErxesForm.tsx:245
Dangerous innerhtml
apps/frontline-widgets/src/app/messenger/components/conversation.tsx:122
Dangerous innerhtml
apps/posclient-front/app/reciept/components/footer.tsx:24
Dangerous innerhtml
apps/posclient-front/app/reciept/components/header.tsx:75
Dangerous innerhtml
apps/posclient-front/app/reciept/cover/page.tsx:143
Dangerous innerhtml
apps/posclient-front/modules/products/components/productItem/productItem.coffeeShop.tsx:141
Dangerous innerhtml
backend/plugins/frontline_api/src/public/widget/messengerWidget.bundle.js:49
Dangerous innerhtml
frontend/core-ui/src/modules/automations/components/builder/nodes/actions/sendEmail/components/SendEmailActionResult.tsx:91
Dangerous innerhtml
frontend/libs/erxes-ui/src/components/charts.tsx:79
Dangerous innerhtml
frontend/libs/erxes-ui/src/modules/blocks/components/BlockEditorReadOnly.tsx:35
Dangerous innerhtml
frontend/libs/ui-modules/src/modules/internal-notes/components/InternalNoteDisplay.tsx:7
Dangerous innerhtml
frontend/plugins/frontline_ui/src/modules/forms/components/FormPreview.tsx:237
Dangerous innerhtml
frontend/plugins/frontline_ui/src/modules/integrations/facebook/components/FacebookPostTrigger.tsx:30
Dangerous innerhtml
frontend/plugins/frontline_ui/src/modules/integrations/instagram/components/IgPostTrigger.tsx:30
Dangerous innerhtml
backend/plugins/frontline_api/src/modules/integrations/imap/imapClient.ts
Ports
apps/frontline-widgets/src/messengerBundle.js:2, 116 (2 hits)apps/frontline-widgets/src/app/form/live-form.tsx:55apps/frontline-widgets/src/app/messenger/ticket/graphql/mutations.ts:4apps/frontline-widgets/src/messenger-widget.js:254apps/posclient-front/app/(main)/cover/components/tdb.tsx:22apps/posclient-front/modules/apolloClientMain.tsx:7apps/posclient-front/modules/auth/configsFetch.tsx:3llms.txt
humans.txt
robots.txt
sitemap.xml
frontend/core-ui/Dockerfile:1
containersPinned dependencies
apps/frontline-widgets/Dockerfile:2
containersPinned dependencies
frontend/core-ui/Dockerfile:19
containersPinned dependencies
apps/frontline-widgets/Dockerfile:19
containersPinned dependencies
apps/posclient-front/Dockerfile:1, 7 (2 hits)apps/frontline-widgets/Dockerfile:10backend/services/logs/Dockerfile:2frontend/core-ui/Dockerfile:11backend/core-api/Dockerfile:2, 41 (2 hits)backend/plugins/accounting_api/Dockerfile:2, 41 (2 hits)backend/plugins/content_api/Dockerfile:2, 42 (2 hits)backend/plugins/frontline_api/Dockerfile:2, 41 (2 hits)backend/plugins/insurance_api/Dockerfile:3, 45 (2 hits)backend/plugins/loyalty_api/Dockerfile:2, 41 (2 hits)backend/plugins/mongolian_api/Dockerfile:2, 41 (2 hits)backend/plugins/operation_api/Dockerfile:2, 41 (2 hits)backend/gateway/Dockerfile:2, 31, 61 (3 hits)frontend/plugins/insurance_ui/src/modules/insurance/components/ContractForm.tsx:184
Document write
frontend/plugins/insurance_ui/src/modules/insurance/components/ProductForm.tsx:550
Document write
frontend/plugins/insurance_ui/src/pages/insurance/ContractPdfEditorPage.tsx:67
Document write
frontend/plugins/insurance_ui/src/utils/contractPdfGenerator.ts:330
Document write
frontend/plugins/mongolian_ui/src/modules/productplaces/containers/ResponseContainer.tsx:83
Document write
frontend/plugins/mongolian_ui/src/pages/EbarimtRespondedPage.tsx:48
Document write
frontend/plugins/mongolian_ui/src/pages/productplaces/ProductPlacesRespondedPage.tsx:31
Document write
Showing first 300 of 390. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/b925c108-67c6-44cc-b208-3b57b7f7314c/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b925c108-67c6-44cc-b208-3b57b7f7314c/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.