{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-34eebf0396f3ab48", "name": "Stray `console.log` in TS/JS \u2014 app.js:105", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app.js:105"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ffa0e7775ffc8ef", "name": "Stray `console.log` in TS/JS \u2014 routes/db.js:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 routes/db.js:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e08c2ce89c01acb", "name": "Stray `console.log` in TS/JS \u2014 routes/api.js:115", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 routes/api.js:115"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-266345742889006e", "name": "Insecure pattern 'cors_wildcard' in app.js:38", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in app.js:38"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d2ee0327feed4ad", "name": "Very large file: routes/api.js (1358 lines)", "shortDescription": {"text": "Very large file: routes/api.js (1358 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 4 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 24 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fe16dcd290c10744", "name": "`fetch()` without try/.catch or AbortSignal \u2014 routes/api.js:8", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 routes/api.js:8"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a60160c08a4d6de8", "name": "Dangling fetch: POST https://stuoa-warning.shakenokirimi12.workers.dev/ (app.js:96)", "shortDescription": {"text": "Dangling fetch: POST https://stuoa-warning.shakenokirimi12.workers.dev/ (app.js:96)"}, "fullDescription": {"text": "`app.js:96` calls `POST https://stuoa-warning.shakenokirimi12.workers.dev/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/stuoa-warning.shakenokirimi12.workers.dev`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6891e071372eff7a", "name": "Unused endpoint: USE /adminui", "shortDescription": {"text": "Unused endpoint: USE /adminui"}, "fullDescription": {"text": "`app.js` declares `USE /adminui` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e68b6a21348203d", "name": "Unused endpoint: USE /mobileui", "shortDescription": {"text": "Unused endpoint: USE /mobileui"}, "fullDescription": {"text": "`app.js` declares `USE /mobileui` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`app.js` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`routes/adminui.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13cbe9625de16d20", "name": "Unused endpoint: GET /adminui/errorcheck", "shortDescription": {"text": "Unused endpoint: GET /adminui/errorcheck"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/errorcheck` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f4ee043e828feb89", "name": "Unused endpoint: POST /adminui/errorsolve", "shortDescription": {"text": "Unused endpoint: POST /adminui/errorsolve"}, "fullDescription": {"text": "`routes/api.js` declares `POST /adminui/errorsolve` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be71cb67cfd25d25", "name": "Unused endpoint: GET /adminui/errorHistory", "shortDescription": {"text": "Unused endpoint: GET /adminui/errorHistory"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/errorHistory` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c86075b5c52f30c", "name": "Unused endpoint: GET /adminui/roomStatus/:roomCode", "shortDescription": {"text": "Unused endpoint: GET /adminui/roomStatus/:roomCode"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/roomStatus/:roomCode` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a678ec9d71c80aa", "name": "Unused endpoint: GET /adminui/getQueueStatus", "shortDescription": {"text": "Unused endpoint: GET /adminui/getQueueStatus"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/getQueueStatus` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ded4729717ad5724", "name": "Unused endpoint: POST /adminui/setGuidedStatus/:ChallengeId", "shortDescription": {"text": "Unused endpoint: POST /adminui/setGuidedStatus/:ChallengeId"}, "fullDescription": {"text": "`routes/api.js` declares `POST /adminui/setGuidedStatus/:ChallengeId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91ba90cd6718e9c2", "name": "Unused endpoint: POST /adminui/regChallenge/auto", "shortDescription": {"text": "Unused endpoint: POST /adminui/regChallenge/auto"}, "fullDescription": {"text": "`routes/api.js` declares `POST /adminui/regChallenge/auto` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-242eefe2ac217f67", "name": "Unused endpoint: DELETE /adminui/rooms/delete/:ChallengeId", "shortDescription": {"text": "Unused endpoint: DELETE /adminui/rooms/delete/:ChallengeId"}, "fullDescription": {"text": "`routes/api.js` declares `DELETE /adminui/rooms/delete/:ChallengeId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-858195fe9562093f", "name": "Unused endpoint: GET /adminui/groups/list", "shortDescription": {"text": "Unused endpoint: GET /adminui/groups/list"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/groups/list` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-931d5744fb218fb4", "name": "Unused endpoint: GET /adminui/groups/:GroupId", "shortDescription": {"text": "Unused endpoint: GET /adminui/groups/:GroupId"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/groups/:GroupId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-360784aeb95897c6", "name": "Unused endpoint: GET /adminui/groups/:GroupId/getCertificate", "shortDescription": {"text": "Unused endpoint: GET /adminui/groups/:GroupId/getCertificate"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/groups/:GroupId/getCertificate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b199e2f02774a39", "name": "Unused endpoint: GET /adminui/groups/:GroupId/getCertificate/re", "shortDescription": {"text": "Unused endpoint: GET /adminui/groups/:GroupId/getCertificate/re"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/groups/:GroupId/getCertificate/re` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d40f49e69a79dd11", "name": "Unused endpoint: GET /adminui/groups/:GroupId/giveSnack", "shortDescription": {"text": "Unused endpoint: GET /adminui/groups/:GroupId/giveSnack"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/groups/:GroupId/giveSnack` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-604badd7b5341716", "name": "Unused endpoint: GET /adminui/getpdf/:filename", "shortDescription": {"text": "Unused endpoint: GET /adminui/getpdf/:filename"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/getpdf/:filename` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5beedd3a0780e9fb", "name": "Unused endpoint: GET /adminui/rooms/list", "shortDescription": {"text": "Unused endpoint: GET /adminui/rooms/list"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/rooms/list` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15f13320c0991f02", "name": "Unused endpoint: GET /adminui/stats/Questions", "shortDescription": {"text": "Unused endpoint: GET /adminui/stats/Questions"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/stats/Questions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-847dda4afd9cd663", "name": "Unused endpoint: GET /adminui/stats/:QuestionId", "shortDescription": {"text": "Unused endpoint: GET /adminui/stats/:QuestionId"}, "fullDescription": {"text": "`routes/api.js` declares `GET /adminui/stats/:QuestionId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2ad106be112f415", "name": "Unused endpoint: POST /client/answer/register", "shortDescription": {"text": "Unused endpoint: POST /client/answer/register"}, "fullDescription": {"text": "`routes/api.js` declares `POST /client/answer/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae5453354467a0b0", "name": "Unused endpoint: POST /client/finish/:roomCode", "shortDescription": {"text": "Unused endpoint: POST /client/finish/:roomCode"}, "fullDescription": {"text": "`routes/api.js` declares `POST /client/finish/:roomCode` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38e1a1a4b222c43b", "name": "Unused endpoint: GET /client/filelist", "shortDescription": {"text": "Unused endpoint: GET /client/filelist"}, "fullDescription": {"text": "`routes/api.js` declares `GET /client/filelist` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bd988e8229be1c1", "name": "Unused endpoint: GET /client/getfile/:filename", "shortDescription": {"text": "Unused endpoint: GET /client/getfile/:filename"}, "fullDescription": {"text": "`routes/api.js` declares `GET /client/getfile/:filename` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-043945e4c62e0e15", "name": "Unused endpoint: GET /client/startGame/:roomCode", "shortDescription": {"text": "Unused endpoint: GET /client/startGame/:roomCode"}, "fullDescription": {"text": "`routes/api.js` declares `GET /client/startGame/:roomCode` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abfd79d8c50836d0", "name": "Unused endpoint: GET /client/:GroupId/getQuestion/:level", "shortDescription": {"text": "Unused endpoint: GET /client/:GroupId/getQuestion/:level"}, "fullDescription": {"text": "`routes/api.js` declares `GET /client/:GroupId/getQuestion/:level` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2bf1905493f1d983", "name": "Unused endpoint: GET /client/getQuestionById/:questionid", "shortDescription": {"text": "Unused endpoint: GET /client/getQuestionById/:questionid"}, "fullDescription": {"text": "`routes/api.js` declares `GET /client/getQuestionById/:questionid` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-224e28a280a6024a", "name": "Unused endpoint: POST /client/errorReport", "shortDescription": {"text": "Unused endpoint: POST /client/errorReport"}, "fullDescription": {"text": "`routes/api.js` declares `POST /client/errorReport` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e5f73c0466773e1", "name": "Unused endpoint: GET /plug/:ip/on", "shortDescription": {"text": "Unused endpoint: GET /plug/:ip/on"}, "fullDescription": {"text": "`routes/api.js` declares `GET /plug/:ip/on` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc87f9a5870d94d4", "name": "Unused endpoint: GET /plug/list", "shortDescription": {"text": "Unused endpoint: GET /plug/list"}, "fullDescription": {"text": "`routes/api.js` declares `GET /plug/list` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a29478f3ec58044a", "name": "Unused endpoint: GET /plug/:ip/off", "shortDescription": {"text": "Unused endpoint: GET /plug/:ip/off"}, "fullDescription": {"text": "`routes/api.js` declares `GET /plug/:ip/off` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f753fd3817bd55d", "name": "Unused endpoint: GET /plug/:ip/switch", "shortDescription": {"text": "Unused endpoint: GET /plug/:ip/switch"}, "fullDescription": {"text": "`routes/api.js` declares `GET /plug/:ip/switch` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc5c0b427bb9f9a7", "name": "Unused endpoint: GET /plug/:ip/switch/loop/:count", "shortDescription": {"text": "Unused endpoint: GET /plug/:ip/switch/loop/:count"}, "fullDescription": {"text": "`routes/api.js` declares `GET /plug/:ip/switch/loop/:count` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-631b17124c8fa982", "name": "Unused endpoint: GET /cleartimes", "shortDescription": {"text": "Unused endpoint: GET /cleartimes"}, "fullDescription": {"text": "`routes/api.js` declares `GET /cleartimes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16e4d0ca3043d467", "name": "Unused endpoint: GET /alive", "shortDescription": {"text": "Unused endpoint: GET /alive"}, "fullDescription": {"text": "`routes/api.js` declares `GET /alive` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19360"}, "properties": {"repository": "Shakenokirimi12/stuoa-server", "repoUrl": "https://github.com/Shakenokirimi12/stuoa-server", "branch": "main"}, "results": [{"ruleId": "scanner-34eebf0396f3ab48", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app.js:105"}, "properties": {"repobilityId": "59748ac0372fad2e", "scanner": "scanner-primary", "fingerprint": "34eebf0396f3ab48", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6ffa0e7775ffc8ef", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 routes/db.js:8"}, "properties": {"repobilityId": "beedc4c33f27c0c6", "scanner": "scanner-primary", "fingerprint": "6ffa0e7775ffc8ef", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9e08c2ce89c01acb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 routes/api.js:115"}, "properties": {"repobilityId": "7cd04de61541bc73", "scanner": "scanner-primary", "fingerprint": "9e08c2ce89c01acb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-266345742889006e", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in app.js:38"}, "properties": {"repobilityId": "cdfa196e8cc349fe", "scanner": "scanner-primary", "fingerprint": "266345742889006e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app.js"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6d2ee0327feed4ad", "level": "note", "message": {"text": "Very large file: routes/api.js (1358 lines)"}, "properties": {"repobilityId": "142eaf374b36cd6f", "scanner": "scanner-primary", "fingerprint": "6d2ee0327feed4ad", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "28a091dd92634695", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "1617353ae2ba750d", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "8ba5fddd8d25c1c1", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "21340d5d4f53d36b", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "bbb6f033901b4967", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "67ec2d5a70d2fcf1", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-fe16dcd290c10744", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 routes/api.js:8"}, "properties": {"repobilityId": "a8b0adc25e7abd9b", "scanner": "scanner-primary", "fingerprint": "fe16dcd290c10744", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a60160c08a4d6de8", "level": "error", "message": {"text": "Dangling fetch: POST https://stuoa-warning.shakenokirimi12.workers.dev/ (app.js:96)"}, "properties": {"repobilityId": "4b0256525397358a", "scanner": "scanner-primary", "fingerprint": "a60160c08a4d6de8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6891e071372eff7a", "level": "note", "message": {"text": "Unused endpoint: USE /adminui"}, "properties": {"repobilityId": "db976181c38b112e", "scanner": "scanner-primary", "fingerprint": "6891e071372eff7a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6e68b6a21348203d", "level": "note", "message": {"text": "Unused endpoint: USE /mobileui"}, "properties": {"repobilityId": "361ff63556567b91", "scanner": "scanner-primary", "fingerprint": "6e68b6a21348203d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "7383953229c321a9", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "0d53bcc4b8e64008", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-13cbe9625de16d20", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/errorcheck"}, "properties": {"repobilityId": "14b3bc609f55ec3a", "scanner": "scanner-primary", "fingerprint": "13cbe9625de16d20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f4ee043e828feb89", "level": "note", "message": {"text": "Unused endpoint: POST /adminui/errorsolve"}, "properties": {"repobilityId": "4c7afacb788d86aa", "scanner": "scanner-primary", "fingerprint": "f4ee043e828feb89", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-be71cb67cfd25d25", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/errorHistory"}, "properties": {"repobilityId": "e94b4c231b3f11b0", "scanner": "scanner-primary", "fingerprint": "be71cb67cfd25d25", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0c86075b5c52f30c", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/roomStatus/:roomCode"}, "properties": {"repobilityId": "6fc40cc57481587a", "scanner": "scanner-primary", "fingerprint": "0c86075b5c52f30c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4a678ec9d71c80aa", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/getQueueStatus"}, "properties": {"repobilityId": "52f19397a42e7979", "scanner": "scanner-primary", "fingerprint": "4a678ec9d71c80aa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ded4729717ad5724", "level": "note", "message": {"text": "Unused endpoint: POST /adminui/setGuidedStatus/:ChallengeId"}, "properties": {"repobilityId": "104e28d59794ef62", "scanner": "scanner-primary", "fingerprint": "ded4729717ad5724", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-91ba90cd6718e9c2", "level": "note", "message": {"text": "Unused endpoint: POST /adminui/regChallenge/auto"}, "properties": {"repobilityId": "901cd0e5d4b34348", "scanner": "scanner-primary", "fingerprint": "91ba90cd6718e9c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-242eefe2ac217f67", "level": "note", "message": {"text": "Unused endpoint: DELETE /adminui/rooms/delete/:ChallengeId"}, "properties": {"repobilityId": "881ad6ce70380d93", "scanner": "scanner-primary", "fingerprint": "242eefe2ac217f67", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-858195fe9562093f", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/groups/list"}, "properties": {"repobilityId": "2f8761bd6af3077f", "scanner": "scanner-primary", "fingerprint": "858195fe9562093f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-931d5744fb218fb4", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/groups/:GroupId"}, "properties": {"repobilityId": "51ae2eb9bf1d373e", "scanner": "scanner-primary", "fingerprint": "931d5744fb218fb4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-360784aeb95897c6", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/groups/:GroupId/getCertificate"}, "properties": {"repobilityId": "765d074b242a06a1", "scanner": "scanner-primary", "fingerprint": "360784aeb95897c6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b199e2f02774a39", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/groups/:GroupId/getCertificate/re"}, "properties": {"repobilityId": "486106a720ab8e39", "scanner": "scanner-primary", "fingerprint": "0b199e2f02774a39", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d40f49e69a79dd11", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/groups/:GroupId/giveSnack"}, "properties": {"repobilityId": "d5046dd7daab88fb", "scanner": "scanner-primary", "fingerprint": "d40f49e69a79dd11", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-604badd7b5341716", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/getpdf/:filename"}, "properties": {"repobilityId": "70575003aec73f45", "scanner": "scanner-primary", "fingerprint": "604badd7b5341716", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5beedd3a0780e9fb", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/rooms/list"}, "properties": {"repobilityId": "215222502c3944f2", "scanner": "scanner-primary", "fingerprint": "5beedd3a0780e9fb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-15f13320c0991f02", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/stats/Questions"}, "properties": {"repobilityId": "713d7d7a4f913959", "scanner": "scanner-primary", "fingerprint": "15f13320c0991f02", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-847dda4afd9cd663", "level": "note", "message": {"text": "Unused endpoint: GET /adminui/stats/:QuestionId"}, "properties": {"repobilityId": "de48a6318e084b0e", "scanner": "scanner-primary", "fingerprint": "847dda4afd9cd663", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d2ad106be112f415", "level": "note", "message": {"text": "Unused endpoint: POST /client/answer/register"}, "properties": {"repobilityId": "7a0ac4a8775c1184", "scanner": "scanner-primary", "fingerprint": "d2ad106be112f415", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ae5453354467a0b0", "level": "note", "message": {"text": "Unused endpoint: POST /client/finish/:roomCode"}, "properties": {"repobilityId": "eb6ea40aa3ef89fd", "scanner": "scanner-primary", "fingerprint": "ae5453354467a0b0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-38e1a1a4b222c43b", "level": "note", "message": {"text": "Unused endpoint: GET /client/filelist"}, "properties": {"repobilityId": "b91854d1130b47d8", "scanner": "scanner-primary", "fingerprint": "38e1a1a4b222c43b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6bd988e8229be1c1", "level": "note", "message": {"text": "Unused endpoint: GET /client/getfile/:filename"}, "properties": {"repobilityId": "2df5c0a124e4743d", "scanner": "scanner-primary", "fingerprint": "6bd988e8229be1c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-043945e4c62e0e15", "level": "note", "message": {"text": "Unused endpoint: GET /client/startGame/:roomCode"}, "properties": {"repobilityId": "e1fe87df62bdbf7d", "scanner": "scanner-primary", "fingerprint": "043945e4c62e0e15", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-abfd79d8c50836d0", "level": "note", "message": {"text": "Unused endpoint: GET /client/:GroupId/getQuestion/:level"}, "properties": {"repobilityId": "9bda06d0a679bc07", "scanner": "scanner-primary", "fingerprint": "abfd79d8c50836d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2bf1905493f1d983", "level": "note", "message": {"text": "Unused endpoint: GET /client/getQuestionById/:questionid"}, "properties": {"repobilityId": "226ef543aba4075b", "scanner": "scanner-primary", "fingerprint": "2bf1905493f1d983", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-224e28a280a6024a", "level": "note", "message": {"text": "Unused endpoint: POST /client/errorReport"}, "properties": {"repobilityId": "ab525a3c8420add6", "scanner": "scanner-primary", "fingerprint": "224e28a280a6024a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6e5f73c0466773e1", "level": "note", "message": {"text": "Unused endpoint: GET /plug/:ip/on"}, "properties": {"repobilityId": "32386ef4927e57e6", "scanner": "scanner-primary", "fingerprint": "6e5f73c0466773e1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bc87f9a5870d94d4", "level": "note", "message": {"text": "Unused endpoint: GET /plug/list"}, "properties": {"repobilityId": "62f1e08825fa3a61", "scanner": "scanner-primary", "fingerprint": "bc87f9a5870d94d4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a29478f3ec58044a", "level": "note", "message": {"text": "Unused endpoint: GET /plug/:ip/off"}, "properties": {"repobilityId": "79c5782d19608348", "scanner": "scanner-primary", "fingerprint": "a29478f3ec58044a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0f753fd3817bd55d", "level": "note", "message": {"text": "Unused endpoint: GET /plug/:ip/switch"}, "properties": {"repobilityId": "a3b3d6744a741f4e", "scanner": "scanner-primary", "fingerprint": "0f753fd3817bd55d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cc5c0b427bb9f9a7", "level": "note", "message": {"text": "Unused endpoint: GET /plug/:ip/switch/loop/:count"}, "properties": {"repobilityId": "758e56e0d99c548e", "scanner": "scanner-primary", "fingerprint": "cc5c0b427bb9f9a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-631b17124c8fa982", "level": "note", "message": {"text": "Unused endpoint: GET /cleartimes"}, "properties": {"repobilityId": "d09ed1c4ceee5561", "scanner": "scanner-primary", "fingerprint": "631b17124c8fa982", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-16e4d0ca3043d467", "level": "note", "message": {"text": "Unused endpoint: GET /alive"}, "properties": {"repobilityId": "819c70fdc07c00a8", "scanner": "scanner-primary", "fingerprint": "16e4d0ca3043d467", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}