Scan timing: clone 21.12s · analysis 21.17s · 43.8 MB · GitHub API rate-limit (preflight)
https://github.com/FlowiseAI/Flowise
· scanned 2026-06-05 11:20 UTC (5 days, 12 hours ago)
· 10 languages
790 raw signals (202 security + 588 graph) 11/13 scanners ran 67th percentile · Typescript · large (100-500K LoC) System graph score 52 (higher by 27)
Last scanned 5 days, 12 hours ago · v2 · 362 actionable findings from 2 signal sources. 134 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
47.0 | 0.20 | 9.40 |
documentation_score |
83.0 | 0.15 | 12.45 |
practices_score |
100.0 | 0.15 | 15.00 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 78.8 |
Showing 283 of 362 actionable findings. 496 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/server/src/enterprise/middleware/passport/index.ts:289
packages/server/marketplaces/agentflowsv2/SQL Agent.json:287, 916 (2 hits)packages/server/src/enterprise/Interface.Enterprise.ts:88
packages/server/src/utils/constants.ts:66
packages/ui/src/store/constant.js:35
packages/server/src/routes/validation/index.ts:6
packages/server/src/routes/attachments/index.ts:8
packages/components/nodes/documentloaders/Folder/Folder.ts:159
packages/server/src/enterprise/routes/organization-user.route.ts:15packages/server/src/enterprise/routes/role.route.ts:14packages/server/src/enterprise/routes/workspace-user.route.ts:26packages/server/src/enterprise/routes/account.route.ts:33
packages/server/src/enterprise/routes/login-method.route.ts:12packages/server/src/enterprise/routes/organization-user.route.ts:11packages/server/src/enterprise/routes/role.route.ts:10packages/server/src/enterprise/routes/workspace-user.route.ts:12packages/server/src/enterprise/routes/workspace.route.ts:11packages/server/src/enterprise/routes/account.route.ts:31
packages/server/src/enterprise/routes/account.route.ts:23
packages/server/src/enterprise/routes/account.route.ts:27
packages/server/src/enterprise/routes/account.route.ts:12
packages/server/src/enterprise/routes/account.route.ts:19
packages/server/src/enterprise/routes/account.route.ts:9
packages/server/src/enterprise/routes/account.route.ts:25
packages/server/src/enterprise/routes/account.route.ts:29
packages/server/src/enterprise/routes/workspace.route.ts:14
packages/server/src/enterprise/routes/login-method.route.ts:16
packages/server/src/enterprise/routes/account.route.ts:21
packages/server/src/enterprise/routes/login-method.route.ts:14packages/server/src/enterprise/routes/organization-user.route.ts:13packages/server/src/enterprise/routes/role.route.ts:12packages/server/src/enterprise/routes/workspace-user.route.ts:19packages/server/src/enterprise/routes/workspace.route.ts:16Dockerfile:6docker/Dockerfile:2docker/worker/Dockerfile:1packages/observe/examples/package-lock.json:1
packages/agentflow/examples/package-lock.json:1
packages/server/src/services/mcp-endpoint/index.ts:143
packages/agentflow/src/core/utils/nodeFactory.ts:69
packages/components/nodes/tools/GoogleDrive/GoogleDrive.ts:153
.github/workflows/publish-package.yml:48, 53, 123, 128 (4 hits).github/workflows/main.yml:22, 27 (3 hits).github/workflows/docker-image-dockerhub.yml:30 (2 hits).github/workflows/docker-image-ecr.yml:43 (2 hits).github/workflows/proprietary-path-guard.yml:38 (2 hits).github/workflows/test_docker_build.yml:18packages/components/src/pythonCodeValidator.ts:51
Exec used
packages/server/src/enterprise/routes/organization-user.route.ts:15
packages/server/src/enterprise/routes/workspace-user.route.ts:10
packages/server/src/enterprise/routes/organization-user.route.ts:11
packages/server/src/enterprise/routes/account.route.ts:19
packages/server/src/enterprise/routes/account.route.ts:9
packages/server/src/enterprise/routes/workspace.route.ts:14
packages/server/src/enterprise/routes/organization-user.route.ts:13
packages/server/src/enterprise/routes/account.route.ts:33
packages/server/src/enterprise/routes/login-method.route.ts:8
packages/server/src/enterprise/routes/login-method.route.ts:10
packages/server/src/enterprise/routes/login-method.route.ts:12
packages/server/src/enterprise/routes/account.route.ts:31
packages/server/src/enterprise/routes/account.route.ts:23
packages/server/src/enterprise/routes/account.route.ts:25
packages/server/src/enterprise/routes/login-method.route.ts:16
packages/server/src/enterprise/routes/account.route.ts:21
packages/server/src/enterprise/routes/login-method.route.ts:14
packages/server/src/controllers/webhook-listener/index.ts:80packages/server/src/services/mcp-endpoint/index.ts:318packages/server/src/services/webhook-listener/registry.ts:98packages/ui/src/layout/MainLayout/Sidebar/CloudMenuList.jsx:41packages/ui/src/store/actions.js:40packages/ui/src/ui-component/dialog/ExportAsTemplateDialog.jsx:103packages/components/credentials/IBMWatsonx.credential.ts:54
packages/server/src/services/nodes/index.ts:114
packages/components/nodes/tools/MCP/CustomMcpServerTool/CustomMcpServerTool.ts:76
docker/worker/docker-compose.yml
CI/CD securitycontainers
docker/docker-compose.yml
CI/CD securitycontainers
docker/worker/Dockerfile:1
CI/CD securitycontainers
docker/Dockerfile:13
CI/CD securitycontainers
docker/worker/Dockerfile:21
CI/CD securitycontainers
Dockerfile:31
CI/CD securitycontainers
docker/worker/Dockerfile:23
CI/CD securitycontainers
Dockerfile:34
CI/CD securitycontainers
packages/server/src/enterprise/sso/Auth0SSO.ts:40, 41, 42 (3 hits)packages/server/src/enterprise/sso/AzureSSO.ts:12, 13, 14 (3 hits)packages/server/src/enterprise/sso/GithubSSO.ts:8, 9, 10 (3 hits)packages/server/src/enterprise/sso/GoogleSSO.ts:11, 12, 13 (3 hits)packages/server/src/enterprise/middleware/prometheus/index.ts:22, 36 (2 hits)packages/server/src/index.ts:327.github/workflows/docker-image-dockerhub.yml:33, 36, 39, 48, 63 (5 hits).github/workflows/docker-image-ecr.yml:46, 49, 60, 66 (5 hits).github/workflows/main.yml:23, 41, 46 (5 hits).github/workflows/publish-package.yml:49, 124 (2 hits).github/workflows/docker-image-ecr.yml.github/workflows/publish-agentflow.yml.github/workflows/publish-observe.yml.github/workflows/publish-package.ymlpackages/ui/src/ui-component/safe/SafeHTML.jsx:51
Dangerous innerhtml
packages/api-documentation/src/yml/swagger.yml
Ports
packages/api-documentation/src/yml/swagger.yml
Ports
packages/api-documentation/src/yml/swagger.yml
Ports
packages/api-documentation/src/yml/swagger.yml
Ports
.dockerignore
CI/CD securitycontainers
docker/docker-compose.ymldocker/worker/docker-compose.ymlmetrics/otel/compose.yaml:2docker/docker-compose.ymldocker/worker/docker-compose.ymlmetrics/otel/compose.yaml:2packages/agentflow/src/atoms/ScenariosInput.tsx:22, 41 (2 hits)packages/agentflow/src/atoms/StructuredOutputBuilder.tsx:73, 210 (2 hits)packages/components/credentials/GoogleSheetsOAuth2.credential.ts:16, 19 (2 hits)packages/components/credentials/MicrosoftTeamsOAuth2.credential.ts:36, 48 (2 hits)packages/components/nodes/agentflow/HumanInput/HumanInput.ts:17, 105 (2 hits)packages/agentflow/src/atoms/ConditionBuilder.tsx:45packages/agentflow/src/atoms/VariableInput.tsx:40packages/agentflow/src/features/canvas/containers/AgentFlowEdge.tsx:19docker/Dockerfile:13
containersPinned dependencies
Dockerfile:6docker/Dockerfile:2docker/worker/Dockerfile:1package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/d33148df-aaa2-49a7-9b50-965011560982/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/d33148df-aaa2-49a7-9b50-965011560982/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.