Scan timing: clone 6.0s · analysis 6.79s · 16.5 MB · GitHub API rate-limit (preflight)
https://github.com/vitejs/vite
· scanned 2026-05-31 01:26 UTC (5 days, 7 hours ago)
· 10 languages
658 findings (90 legacy + 568 scanner) 67th percentile · Javascript · medium (20-100K LoC) Scanner says 61 (higher by 17)
Last scanned 5 days, 7 hours ago · v2 · last Δ +5.4 (diff) · 364 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
76.0 | 0.25 | 19.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
76.1 | 0.15 | 11.41 |
practices_score |
88.0 | 0.15 | 13.20 |
code_quality |
58.5 | 0.10 | 5.85 |
| Overall | 1.00 | 77.5 |
Showing 295 of 364 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/vite/src/node/ssr/ssrStacktrace.ts:13
qualitylegacy
packages/create-vite/template-vanilla/src/counter.js:5
xsslegacy
packages/create-vite/template-vanilla-ts/src/main.ts:7
xsslegacy
packages/create-vite/template-vanilla-ts/src/counter.ts:5
xsslegacy
packages/vite/src/node/plugins/define.ts:92
qualitylegacy
packages/vite/src/node/plugins/assetImportMetaUrl.ts:66
qualitylegacy
packages/vite/src/node/optimizer/resolve.ts:87
qualitylegacy
packages/vite/src/module-runner/evaluatedModules.ts:117
qualitylegacy
packages/vite/src/client/overlay.ts:272
qualitylegacy
packages/vite/rolldown.config.ts:252
qualitylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/optimize-deps-no-discovery/package.json:1
dependencylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/optimize-deps/package.json:1
dependencylegacy
playground/alias/package.json:1
dependencylegacy
packages/create-vite/src/index.ts:872
owaspexec_used
packages/vite/src/node/server/openBrowser.ts:141
owaspexec_used
packages/vite/src/node/server/environment.ts:375
error_handlinglegacy
packages/create-vite/template-preact-ts/src/app.tsx:44
securitylegacy
packages/create-vite/template-lit/src/my-element.js:63
securitylegacy
packages/create-vite/template-lit-ts/src/my-element.ts:57
securitylegacy
packages/vite/src/node/utils.ts:8
qualitylegacy
packages/vite/src/node/server/index.ts:78
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
.github/workflows/copilot-setup-steps.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-tag.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish.yml
supply-chaingithub-actionsleast-privilege
playground/multiple-entrypoints/entrypoints/a12.js:16
qualitylegacy
playground/multiple-entrypoints/entrypoints/a11.js:17
qualitylegacy
playground/multiple-entrypoints/entrypoints/a10.js:18
qualitylegacy
playground/multiple-entrypoints/entrypoints/a1.js:27
qualitylegacy
playground/hmr/vite.config.ts:88
qualitylegacy
playground/fs-serve/root/vite.config.js:13
qualitylegacy
playground/css/vite.config-relative-base.js:1
qualitylegacy
playground/assets/vite.config-url-base.js:14
qualitylegacy
packages/create-vite/template-vue/src/components/HelloWorld.vue:21
qualitylegacy
packages/create-vite/template-vue/src/components/HelloWorld.vue:2
qualitylegacy
packages/create-vite/template-vue-ts/src/components/HelloWorld.vue:21
qualitylegacy
packages/create-vite/template-vanilla/src/main.js:16
qualitylegacy
packages/create-vite/template-svelte/src/App.svelte:37
qualitylegacy
packages/create-vite/template-svelte/src/App.svelte:1
qualitylegacy
packages/create-vite/template-svelte-ts/src/App.svelte:37
qualitylegacy
packages/create-vite/template-solid/src/App.jsx:30
qualitylegacy
packages/create-vite/template-solid/src/App.jsx:28
qualitylegacy
packages/create-vite/template-solid/src/App.jsx:1
qualitylegacy
packages/create-vite/template-solid-ts/src/App.tsx:30
qualitylegacy
packages/create-vite/template-solid-ts/src/App.tsx:28
qualitylegacy
packages/create-vite/template-react/src/App.jsx:1
qualitylegacy
packages/create-vite/template-qwik/src/app.jsx:26
qualitylegacy
packages/create-vite/template-qwik/src/app.jsx:24
qualitylegacy
packages/create-vite/template-qwik/src/app.jsx:1
qualitylegacy
packages/create-vite/template-qwik-ts/src/app.tsx:26
qualitylegacy
packages/create-vite/template-qwik-ts/src/app.tsx:24
qualitylegacy
packages/create-vite/template-preact/src/app.jsx:28
qualitylegacy
packages/create-vite/template-preact/src/app.jsx:1
qualitylegacy
packages/create-vite/template-preact-ts/src/app.tsx:28
qualitylegacy
packages/create-vite/template-lit/src/my-element.js:27
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
package.json
supply-chainnpminstall-scripts
playground/proxy-bypass/vite.config.js:16
qualitylegacy
packages/create-vite/tsdown.config.ts:143
qualitylegacy
packages/vite/scripts/benchCircularImport.ts:59
qualitylegacy
packages/plugin-legacy/src/snippets.ts:3
qualitylegacy
packages/create-vite/template-vanilla-ts/src/main.ts:7
qualitylegacy
packages/vite/src/module-runner/sourcemap/decoder.ts:62
qualitylegacy
packages/vite/src/module-runner/createImportMeta.ts:6
qualitylegacy
docs/.vitepress/theme/index.ts:18
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/ce0b060e-269d-4cad-aeaf-986153a5541a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/ce0b060e-269d-4cad-aeaf-986153a5541a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.