{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-0c6f6036f6d163eb", "name": "Stray `console.log` in TS/JS \u2014 update_routes_mint.js:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 update_routes_mint.js:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8bfa1cfce7a88e7f", "name": "Stray `console.log` in TS/JS \u2014 patch_admin.js:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 patch_admin.js:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e6f2aa795c43016", "name": "Stray `console.log` in TS/JS \u2014 fix_upgrade.js:86", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 fix_upgrade.js:86"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79b7dbea28467c85", "name": "Stray `console.log` in TS/JS \u2014 update_db.js:100", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 update_db.js:100"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7bf57523e6433cff", "name": "Stray `console.log` in TS/JS \u2014 update_routes_qr.js:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 update_routes_qr.js:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe0d2be00f43c6f0", "name": "Stray `console.log` in TS/JS \u2014 fix_manual_levels.js:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 fix_manual_levels.js:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3770da41d70599f0", "name": "Stray `console.log` in TS/JS \u2014 enhance_design.js:109", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 enhance_design.js:109"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b5290cf640011a30", "name": "Stray `console.log` in TS/JS \u2014 check_server.js:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 check_server.js:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a0cf53fd8bb2891", "name": "Stray `console.log` in TS/JS \u2014 server.js:188", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:188"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e28fcf5a0414c6d3", "name": "Stray `console.log` in TS/JS \u2014 fix_qr.js:27", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 fix_qr.js:27"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-990c5396ba7bd82b", "name": "Stray `console.log` in TS/JS \u2014 scripts/update-uri.js:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/update-uri.js:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cce29ba0b6de9b45", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-minter-wallet.js:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-minter-wallet.js:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee06365dd153e8c1", "name": "Stray `console.log` in TS/JS \u2014 routes/admin.js:263", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 routes/admin.js:263"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f479b0bf1602fc4c", "name": "Stray `console.log` in TS/JS \u2014 routes/raffle.js:209", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 routes/raffle.js:209"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-685a8b63296d2967", "name": "Stray `console.log` in TS/JS \u2014 services/push.js:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/push.js:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3abee6e18ae1227e", "name": "Stray `console.log` in TS/JS \u2014 services/polygon.js:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/polygon.js:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-593bdc57755d01ec", "name": "Stray `console.log` in TS/JS \u2014 services/notifications.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/notifications.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-598ae057b18c2ecf", "name": "Stray `console.log` in TS/JS \u2014 services/crossmint.js:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/crossmint.js:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37f82ed36e6c2a76", "name": "Stray `console.log` in TS/JS \u2014 db/database.js:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 db/database.js:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3d18f74123e03959", "name": "Insecure pattern 'direct_innerhtml_assignment' in patch_admin.js:31", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in patch_admin.js:31"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3736ad0f51b60c0", "name": "Insecure pattern 'cors_wildcard' in server.js:20", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in server.js:20"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c76b068ce910ceb6", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/admin/index.html:2366", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/admin/index.html:2366"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e8bc48e439e2e08a", "name": "Insecure pattern 'local_storage_auth_token' in public/admin/index.html:2305", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in public/admin/index.html:2305"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19c8c803bf403556", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/entry/app.js:124", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/entry/app.js:124"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4924238a215f77a3", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/claim/index.html:2763", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/claim/index.html:2763"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-388997ae4660185b", "name": "Very large file: db/database.js (1789 lines)", "shortDescription": {"text": "Very large file: db/database.js (1789 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 31 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 74 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-122f91b7f2906dc4", "name": "Agent authority lacks a verifier contract: .claude/settings.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d0626081ab8d4303", "name": "Commented-code block (8 lines) in update_routes_mint.js:70", "shortDescription": {"text": "Commented-code block (8 lines) in update_routes_mint.js:70"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c79f1c3fc4ca246b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 patch_admin.js:37", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 patch_admin.js:37"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa584b0f6f64666b", "name": "Commented-code block (8 lines) in server.js:155", "shortDescription": {"text": "Commented-code block (8 lines) in server.js:155"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ec66489ff5e35be8", "name": "Commented-code block (7 lines) in routes/admin.js:29", "shortDescription": {"text": "Commented-code block (7 lines) in routes/admin.js:29"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d59af263bce47924", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/crossmint.js:66", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/crossmint.js:66"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0b5e7cb1208a7cd", "name": "13 env vars used in code but missing from .env.example", "shortDescription": {"text": "13 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `APP_URL`, `CROSSMINT_TEMPLATE_N1`, `CROSSMINT_TEMPLATE_N2`, `CROSSMINT_TEMPLATE_N3`, `CROSSMINT_TEMPLATE_N4`, `DB_PATH`, `MINTER_PRIVATE_KEY`, `NFT_CONTRACT_ADDRESS` + 5 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0787050cab94606d", "name": "Dangling fetch: GET /api/raffle/admin/weekly/target-week (patch_admin.js:34)", "shortDescription": {"text": "Dangling fetch: GET /api/raffle/admin/weekly/target-week (patch_admin.js:34)"}, "fullDescription": {"text": "`patch_admin.js:34` calls `GET /api/raffle/admin/weekly/target-week` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/raffle/admin/weekly/target-week`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e37f6b52da80ba28", "name": "Dangling fetch: GET /api/raffle/admin/weekly/all-weeks (patch_admin.js:37)", "shortDescription": {"text": "Dangling fetch: GET /api/raffle/admin/weekly/all-weeks (patch_admin.js:37)"}, "fullDescription": {"text": "`patch_admin.js:37` calls `GET /api/raffle/admin/weekly/all-weeks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/raffle/admin/weekly/all-weeks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d60eaa8bab72904f", "name": "Dangling fetch: POST /api/mint/entry (public/entry/app.js:87)", "shortDescription": {"text": "Dangling fetch: POST /api/mint/entry (public/entry/app.js:87)"}, "fullDescription": {"text": "`public/entry/app.js:87` calls `POST /api/mint/entry` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/mint/entry`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1ac4fcc48ea6230", "name": "Dangling fetch: POST /api/mint/create-wallet (public/entry/app.js:183)", "shortDescription": {"text": "Dangling fetch: POST /api/mint/create-wallet (public/entry/app.js:183)"}, "fullDescription": {"text": "`public/entry/app.js:183` calls `POST /api/mint/create-wallet` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/mint/create-wallet`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-efe32053ae8b6ed9", "name": "Dangling fetch: POST /api/mint/recover-from-phrase (public/entry/app.js:249)", "shortDescription": {"text": "Dangling fetch: POST /api/mint/recover-from-phrase (public/entry/app.js:249)"}, "fullDescription": {"text": "`public/entry/app.js:249` calls `POST /api/mint/recover-from-phrase` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/mint/recover-from-phrase`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-609576db0e130f91", "name": "Unused endpoint: POST /entry", "shortDescription": {"text": "Unused endpoint: POST /entry"}, "fullDescription": {"text": "`update_routes_mint.js` declares `POST /entry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-057ab5b8bba48aaa", "name": "Unused endpoint: GET /entry", "shortDescription": {"text": "Unused endpoint: GET /entry"}, "fullDescription": {"text": "`update_routes_qr.js` declares `GET /entry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1434ec6a6f1ec0cb", "name": "Unused endpoint: GET /entry/download", "shortDescription": {"text": "Unused endpoint: GET /entry/download"}, "fullDescription": {"text": "`update_routes_qr.js` declares `GET /entry/download` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-187fbca56f55be48", "name": "Unused endpoint: USE /claim", "shortDescription": {"text": "Unused endpoint: USE /claim"}, "fullDescription": {"text": "`check_server.js` declares `USE /claim` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0fc3f8c9ba14574d", "name": "Unused endpoint: USE /entry", "shortDescription": {"text": "Unused endpoint: USE /entry"}, "fullDescription": {"text": "`check_server.js` declares `USE /entry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6ece196d2049d3b", "name": "Unused endpoint: USE /api/mint", "shortDescription": {"text": "Unused endpoint: USE /api/mint"}, "fullDescription": {"text": "`server.js` declares `USE /api/mint` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d93a530ce10d47d9", "name": "Unused endpoint: USE /api/admin", "shortDescription": {"text": "Unused endpoint: USE /api/admin"}, "fullDescription": {"text": "`server.js` declares `USE /api/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1b7f3d2328822bb", "name": "Unused endpoint: USE /api/qr", "shortDescription": {"text": "Unused endpoint: USE /api/qr"}, "fullDescription": {"text": "`server.js` declares `USE /api/qr` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12accbc2df839ddd", "name": "Unused endpoint: USE /api/raffle", "shortDescription": {"text": "Unused endpoint: USE /api/raffle"}, "fullDescription": {"text": "`server.js` declares `USE /api/raffle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-538bbf0ab06b039c", "name": "Unused endpoint: USE /api/push", "shortDescription": {"text": "Unused endpoint: USE /api/push"}, "fullDescription": {"text": "`server.js` declares `USE /api/push` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec00984b27c88c15", "name": "Unused endpoint: USE /api/events", "shortDescription": {"text": "Unused endpoint: USE /api/events"}, "fullDescription": {"text": "`server.js` declares `USE /api/events` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-265cf3d9ef4ca37c", "name": "Unused endpoint: USE /api/pdf", "shortDescription": {"text": "Unused endpoint: USE /api/pdf"}, "fullDescription": {"text": "`server.js` declares `USE /api/pdf` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`server.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-953ec1a0ee6df50d", "name": "Unused endpoint: GET /admin", "shortDescription": {"text": "Unused endpoint: GET /admin"}, "fullDescription": {"text": "`server.js` declares `GET /admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d077516b4401e3dc", "name": "Unused endpoint: GET /claim", "shortDescription": {"text": "Unused endpoint: GET /claim"}, "fullDescription": {"text": "`server.js` declares `GET /claim` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bf6522ec31fcde2", "name": "Unused endpoint: GET /nfc", "shortDescription": {"text": "Unused endpoint: GET /nfc"}, "fullDescription": {"text": "`server.js` declares `GET /nfc` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72d9eec4146ada88", "name": "Unused endpoint: GET /nft-metadata/:id", "shortDescription": {"text": "Unused endpoint: GET /nft-metadata/:id"}, "fullDescription": {"text": "`server.js` declares `GET /nft-metadata/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b59435b3211a9df", "name": "Unused endpoint: USE /assets", "shortDescription": {"text": "Unused endpoint: USE /assets"}, "fullDescription": {"text": "`server.js` declares `USE /assets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba44ffb1d2d04cec", "name": "Unused endpoint: USE /prize-images", "shortDescription": {"text": "Unused endpoint: USE /prize-images"}, "fullDescription": {"text": "`server.js` declares `USE /prize-images` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55f21a73fa2a83d2", "name": "Unused endpoint: POST /exit", "shortDescription": {"text": "Unused endpoint: POST /exit"}, "fullDescription": {"text": "`routes/mint.js` declares `POST /exit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d57a5fe4e8ba834d", "name": "Unused endpoint: POST /create-wallet", "shortDescription": {"text": "Unused endpoint: POST /create-wallet"}, "fullDescription": {"text": "`routes/mint.js` declares `POST /create-wallet` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce982210c81785c5", "name": "Unused endpoint: POST /recover-from-phrase", "shortDescription": {"text": "Unused endpoint: POST /recover-from-phrase"}, "fullDescription": {"text": "`routes/mint.js` declares `POST /recover-from-phrase` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`routes/mint.js` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-afc064028ae39ea9", "name": "Unused endpoint: GET /history", "shortDescription": {"text": "Unused endpoint: GET /history"}, "fullDescription": {"text": "`routes/mint.js` declares `GET /history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bdcae47b43f751d9", "name": "Unused endpoint: GET /vapid-public-key", "shortDescription": {"text": "Unused endpoint: GET /vapid-public-key"}, "fullDescription": {"text": "`routes/push.js` declares `GET /vapid-public-key` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-365f0986d17746b8", "name": "Unused endpoint: POST /subscribe", "shortDescription": {"text": "Unused endpoint: POST /subscribe"}, "fullDescription": {"text": "`routes/push.js` declares `POST /subscribe` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`routes/admin.js` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ef6dd1315a3338b", "name": "Unused endpoint: GET /current-message", "shortDescription": {"text": "Unused endpoint: GET /current-message"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /current-message` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d315efa0f1b0f8fb", "name": "Unused endpoint: GET /inbox", "shortDescription": {"text": "Unused endpoint: GET /inbox"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /inbox` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a641ecf39e8431f9", "name": "Unused endpoint: POST /react", "shortDescription": {"text": "Unused endpoint: POST /react"}, "fullDescription": {"text": "`routes/admin.js` declares `POST /react` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd8dc4599ec52a08", "name": "Unused endpoint: GET /stats", "shortDescription": {"text": "Unused endpoint: GET /stats"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2120e295b7fc217c", "name": "Unused endpoint: GET /debug-push", "shortDescription": {"text": "Unused endpoint: GET /debug-push"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /debug-push` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af00171afc55225a", "name": "Unused endpoint: GET /holders", "shortDescription": {"text": "Unused endpoint: GET /holders"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /holders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-078755a1d3f6c729", "name": "Unused endpoint: GET /multilevel", "shortDescription": {"text": "Unused endpoint: GET /multilevel"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /multilevel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e10ffd7f0cecdf1", "name": "Unused endpoint: POST /send-message", "shortDescription": {"text": "Unused endpoint: POST /send-message"}, "fullDescription": {"text": "`routes/admin.js` declares `POST /send-message` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e934dba02d2877a1", "name": "Unused endpoint: GET /messages", "shortDescription": {"text": "Unused endpoint: GET /messages"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /messages` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-094415b878a0fad0", "name": "Unused endpoint: GET /reactions-summary", "shortDescription": {"text": "Unused endpoint: GET /reactions-summary"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /reactions-summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b732547b209572e8", "name": "Unused endpoint: GET /event-sessions", "shortDescription": {"text": "Unused endpoint: GET /event-sessions"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /event-sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7bc7e80a429daad", "name": "Unused endpoint: GET /peak-hours", "shortDescription": {"text": "Unused endpoint: GET /peak-hours"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /peak-hours` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e03a6de6e7f5fe8", "name": "Unused endpoint: GET /funnel", "shortDescription": {"text": "Unused endpoint: GET /funnel"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /funnel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e567912e1835772", "name": "Unused endpoint: GET /segments", "shortDescription": {"text": "Unused endpoint: GET /segments"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /segments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f7819037dd5c100", "name": "Unused endpoint: GET /hourly", "shortDescription": {"text": "Unused endpoint: GET /hourly"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /hourly` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1d4a03ddcfbd438", "name": "Unused endpoint: GET /message-stats", "shortDescription": {"text": "Unused endpoint: GET /message-stats"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /message-stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ddbc8f66d3e2056", "name": "Unused endpoint: GET /report-data", "shortDescription": {"text": "Unused endpoint: GET /report-data"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /report-data` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2edb56c67bd4f621", "name": "Unused endpoint: GET /inspect-wallet/:address", "shortDescription": {"text": "Unused endpoint: GET /inspect-wallet/:address"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /inspect-wallet/:address` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e41cf8e94598cb93", "name": "Unused endpoint: GET /polygon-balance", "shortDescription": {"text": "Unused endpoint: GET /polygon-balance"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /polygon-balance` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d4b15309bc1c224", "name": "Unused endpoint: GET /pending-mints", "shortDescription": {"text": "Unused endpoint: GET /pending-mints"}, "fullDescription": {"text": "`routes/admin.js` declares `GET /pending-mints` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-549722626b5e35eb", "name": "Unused endpoint: POST /reconcile-mints", "shortDescription": {"text": "Unused endpoint: POST /reconcile-mints"}, "fullDescription": {"text": "`routes/admin.js` declares `POST /reconcile-mints` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7acc4e80fcca7ae4", "name": "Unused endpoint: POST /mints/:id/approve", "shortDescription": {"text": "Unused endpoint: POST /mints/:id/approve"}, "fullDescription": {"text": "`routes/admin.js` declares `POST /mints/:id/approve` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f617ab86bb6aa98f", "name": "Unused endpoint: POST /mints/:id/reject", "shortDescription": {"text": "Unused endpoint: POST /mints/:id/reject"}, "fullDescription": {"text": "`routes/admin.js` declares `POST /mints/:id/reject` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21344"}, "properties": {"repository": "titofeca/Furancho-sessions", "repoUrl": "https://github.com/titofeca/Furancho-sessions", "branch": "main"}, "results": [{"ruleId": "scanner-0c6f6036f6d163eb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 update_routes_mint.js:80"}, "properties": {"repobilityId": "09298f866dc1eec8", "scanner": "scanner-primary", "fingerprint": "0c6f6036f6d163eb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8bfa1cfce7a88e7f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 patch_admin.js:98"}, "properties": {"repobilityId": "7f141a61c14b1668", "scanner": "scanner-primary", "fingerprint": "8bfa1cfce7a88e7f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e6f2aa795c43016", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 fix_upgrade.js:86"}, "properties": {"repobilityId": "3711747ba2fed454", "scanner": "scanner-primary", "fingerprint": "5e6f2aa795c43016", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-79b7dbea28467c85", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 update_db.js:100"}, "properties": {"repobilityId": "91d746d388e156ae", "scanner": "scanner-primary", "fingerprint": "79b7dbea28467c85", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7bf57523e6433cff", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 update_routes_qr.js:52"}, "properties": {"repobilityId": "769f25f79ad29fd3", "scanner": "scanner-primary", "fingerprint": "7bf57523e6433cff", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fe0d2be00f43c6f0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 fix_manual_levels.js:34"}, "properties": {"repobilityId": "71fd9072b92ec521", "scanner": "scanner-primary", "fingerprint": "fe0d2be00f43c6f0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3770da41d70599f0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 enhance_design.js:109"}, "properties": {"repobilityId": "9dd4c6254c6c8a8e", "scanner": "scanner-primary", "fingerprint": "3770da41d70599f0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b5290cf640011a30", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 check_server.js:6"}, "properties": {"repobilityId": "3f679fb7b2371793", "scanner": "scanner-primary", "fingerprint": "b5290cf640011a30", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8a0cf53fd8bb2891", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:188"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "8a0cf53fd8bb2891", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e28fcf5a0414c6d3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 fix_qr.js:27"}, "properties": {"repobilityId": "4f1138c5c0e5f0d5", "scanner": "scanner-primary", "fingerprint": "e28fcf5a0414c6d3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-990c5396ba7bd82b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/update-uri.js:20"}, "properties": {"repobilityId": "e18da7cee28d5e3d", "scanner": "scanner-primary", "fingerprint": "990c5396ba7bd82b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cce29ba0b6de9b45", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-minter-wallet.js:5"}, "properties": {"repobilityId": "e0d94a469410bb31", "scanner": "scanner-primary", "fingerprint": "cce29ba0b6de9b45", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ee06365dd153e8c1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 routes/admin.js:263"}, "properties": {"repobilityId": "fcae94c7533b330a", "scanner": "scanner-primary", "fingerprint": "ee06365dd153e8c1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f479b0bf1602fc4c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 routes/raffle.js:209"}, "properties": {"repobilityId": "2094d4a4b1f80a77", "scanner": "scanner-primary", "fingerprint": "f479b0bf1602fc4c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-685a8b63296d2967", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/push.js:25"}, "properties": {"repobilityId": "683c7aa1ca9c9719", "scanner": "scanner-primary", "fingerprint": "685a8b63296d2967", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3abee6e18ae1227e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/polygon.js:25"}, "properties": {"repobilityId": "a98a21f2a73a3b15", "scanner": "scanner-primary", "fingerprint": "3abee6e18ae1227e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-593bdc57755d01ec", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/notifications.js:21"}, "properties": {"repobilityId": "89ade700bebaf068", "scanner": "scanner-primary", "fingerprint": "593bdc57755d01ec", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-598ae057b18c2ecf", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/crossmint.js:42"}, "properties": {"repobilityId": "7a327e13e418f64d", "scanner": "scanner-primary", "fingerprint": "598ae057b18c2ecf", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-37f82ed36e6c2a76", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 db/database.js:14"}, "properties": {"repobilityId": "01c0e797aaf82940", "scanner": "scanner-primary", "fingerprint": "37f82ed36e6c2a76", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-3d18f74123e03959", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in patch_admin.js:31"}, "properties": {"repobilityId": "33bdf3c64b14e470", "scanner": "scanner-primary", "fingerprint": "3d18f74123e03959", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "patch_admin.js"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-e3736ad0f51b60c0", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in server.js:20"}, "properties": {"repobilityId": "0d9bca6c0839725e", "scanner": "scanner-primary", "fingerprint": "e3736ad0f51b60c0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server.js"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-c76b068ce910ceb6", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/admin/index.html:2366"}, "properties": {"repobilityId": "b96af6a0a5f105a2", "scanner": "scanner-primary", "fingerprint": "c76b068ce910ceb6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/admin/index.html"}, "region": {"startLine": 2366}}}]}, {"ruleId": "scanner-e8bc48e439e2e08a", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in public/admin/index.html:2305"}, "properties": {"repobilityId": "5847a6488e850788", "scanner": "scanner-primary", "fingerprint": "e8bc48e439e2e08a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/admin/index.html"}, "region": {"startLine": 2305}}}]}, {"ruleId": "scanner-19c8c803bf403556", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/entry/app.js:124"}, "properties": {"repobilityId": "98a060271d9cbcfe", "scanner": "scanner-primary", "fingerprint": "19c8c803bf403556", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/entry/app.js"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-4924238a215f77a3", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/claim/index.html:2763"}, "properties": {"repobilityId": "2a77d549b0cbf49b", "scanner": "scanner-primary", "fingerprint": "4924238a215f77a3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/claim/index.html"}, "region": {"startLine": 2763}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-388997ae4660185b", "level": "note", "message": {"text": "Very large file: db/database.js (1789 lines)"}, "properties": {"repobilityId": "38338cbb0004931b", "scanner": "scanner-primary", "fingerprint": "388997ae4660185b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "50455226a3b043b1", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "bdda9751ddffdcdf", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "676a0e7482b2df52", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "31836394867635fb", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "66efaf59857fb227", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "720b084c84604245", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "a282daacd88ad040", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-122f91b7f2906dc4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "properties": {"repobilityId": "a2967269048b6a9d", "scanner": "scanner-primary", "fingerprint": "122f91b7f2906dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d0626081ab8d4303", "level": "none", "message": {"text": "Commented-code block (8 lines) in update_routes_mint.js:70"}, "properties": {"repobilityId": "dd1322bacac93576", "scanner": "scanner-primary", "fingerprint": "d0626081ab8d4303", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c79f1c3fc4ca246b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 patch_admin.js:37"}, "properties": {"repobilityId": "6b81b92fbfd48487", "scanner": "scanner-primary", "fingerprint": "c79f1c3fc4ca246b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-aa584b0f6f64666b", "level": "none", "message": {"text": "Commented-code block (8 lines) in server.js:155"}, "properties": {"repobilityId": "945fc1f796b8245f", "scanner": "scanner-primary", "fingerprint": "aa584b0f6f64666b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ec66489ff5e35be8", "level": "none", "message": {"text": "Commented-code block (7 lines) in routes/admin.js:29"}, "properties": {"repobilityId": "26f9a81069fe89d7", "scanner": "scanner-primary", "fingerprint": "ec66489ff5e35be8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d59af263bce47924", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/crossmint.js:66"}, "properties": {"repobilityId": "8854cd7a3d517217", "scanner": "scanner-primary", "fingerprint": "d59af263bce47924", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b0b5e7cb1208a7cd", "level": "note", "message": {"text": "13 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "2737b8666c1f7eeb", "scanner": "scanner-primary", "fingerprint": "b0b5e7cb1208a7cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-0787050cab94606d", "level": "error", "message": {"text": "Dangling fetch: GET /api/raffle/admin/weekly/target-week (patch_admin.js:34)"}, "properties": {"repobilityId": "758121daf530c9db", "scanner": "scanner-primary", "fingerprint": "0787050cab94606d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e37f6b52da80ba28", "level": "error", "message": {"text": "Dangling fetch: GET /api/raffle/admin/weekly/all-weeks (patch_admin.js:37)"}, "properties": {"repobilityId": "fcae1597be73daf0", "scanner": "scanner-primary", "fingerprint": "e37f6b52da80ba28", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d60eaa8bab72904f", "level": "error", "message": {"text": "Dangling fetch: POST /api/mint/entry (public/entry/app.js:87)"}, "properties": {"repobilityId": "3ceee7488690c0db", "scanner": "scanner-primary", "fingerprint": "d60eaa8bab72904f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d1ac4fcc48ea6230", "level": "error", "message": {"text": "Dangling fetch: POST /api/mint/create-wallet (public/entry/app.js:183)"}, "properties": {"repobilityId": "ea73e2b373678ce0", "scanner": "scanner-primary", "fingerprint": "d1ac4fcc48ea6230", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-efe32053ae8b6ed9", "level": "error", "message": {"text": "Dangling fetch: POST /api/mint/recover-from-phrase (public/entry/app.js:249)"}, "properties": {"repobilityId": "327a755c8b28eecb", "scanner": "scanner-primary", "fingerprint": "efe32053ae8b6ed9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-609576db0e130f91", "level": "note", "message": {"text": "Unused endpoint: POST /entry"}, "properties": {"repobilityId": "8212f00329cecbf1", "scanner": "scanner-primary", "fingerprint": "609576db0e130f91", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-057ab5b8bba48aaa", "level": "note", "message": {"text": "Unused endpoint: GET /entry"}, "properties": {"repobilityId": "e83d313ef82bf5d0", "scanner": "scanner-primary", "fingerprint": "057ab5b8bba48aaa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1434ec6a6f1ec0cb", "level": "note", "message": {"text": "Unused endpoint: GET /entry/download"}, "properties": {"repobilityId": "33f5ada1bcb0374a", "scanner": "scanner-primary", "fingerprint": "1434ec6a6f1ec0cb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-187fbca56f55be48", "level": "note", "message": {"text": "Unused endpoint: USE /claim"}, "properties": {"repobilityId": "9c3e91b4514459e4", "scanner": "scanner-primary", "fingerprint": "187fbca56f55be48", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0fc3f8c9ba14574d", "level": "note", "message": {"text": "Unused endpoint: USE /entry"}, "properties": {"repobilityId": "27a62715faab397e", "scanner": "scanner-primary", "fingerprint": "0fc3f8c9ba14574d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b6ece196d2049d3b", "level": "note", "message": {"text": "Unused endpoint: USE /api/mint"}, "properties": {"repobilityId": "f6aad4e43df1845c", "scanner": "scanner-primary", "fingerprint": "b6ece196d2049d3b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d93a530ce10d47d9", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin"}, "properties": {"repobilityId": "7cf1ce4709c13e8a", "scanner": "scanner-primary", "fingerprint": "d93a530ce10d47d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1b7f3d2328822bb", "level": "note", "message": {"text": "Unused endpoint: USE /api/qr"}, "properties": {"repobilityId": "78d5485fa8d31f4f", "scanner": "scanner-primary", "fingerprint": "e1b7f3d2328822bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-12accbc2df839ddd", "level": "note", "message": {"text": "Unused endpoint: USE /api/raffle"}, "properties": {"repobilityId": "11db8a3177f22f69", "scanner": "scanner-primary", "fingerprint": "12accbc2df839ddd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-538bbf0ab06b039c", "level": "note", "message": {"text": "Unused endpoint: USE /api/push"}, "properties": {"repobilityId": "e669dec21b932e46", "scanner": "scanner-primary", "fingerprint": "538bbf0ab06b039c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ec00984b27c88c15", "level": "note", "message": {"text": "Unused endpoint: USE /api/events"}, "properties": {"repobilityId": "318795c55bc38b12", "scanner": "scanner-primary", "fingerprint": "ec00984b27c88c15", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-265cf3d9ef4ca37c", "level": "note", "message": {"text": "Unused endpoint: USE /api/pdf"}, "properties": {"repobilityId": "cb5a7bb4f7447f75", "scanner": "scanner-primary", "fingerprint": "265cf3d9ef4ca37c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9b883326e67da4e4", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-953ec1a0ee6df50d", "level": "note", "message": {"text": "Unused endpoint: GET /admin"}, "properties": {"repobilityId": "20a301044ef91485", "scanner": "scanner-primary", "fingerprint": "953ec1a0ee6df50d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d077516b4401e3dc", "level": "note", "message": {"text": "Unused endpoint: GET /claim"}, "properties": {"repobilityId": "cc2b207409cb5d73", "scanner": "scanner-primary", "fingerprint": "d077516b4401e3dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bf6522ec31fcde2", "level": "note", "message": {"text": "Unused endpoint: GET /nfc"}, "properties": {"repobilityId": "8c2b474584062927", "scanner": "scanner-primary", "fingerprint": "1bf6522ec31fcde2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-72d9eec4146ada88", "level": "note", "message": {"text": "Unused endpoint: GET /nft-metadata/:id"}, "properties": {"repobilityId": "668bb421e2fd6b84", "scanner": "scanner-primary", "fingerprint": "72d9eec4146ada88", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b59435b3211a9df", "level": "note", "message": {"text": "Unused endpoint: USE /assets"}, "properties": {"repobilityId": "1b8fb48245d8339a", "scanner": "scanner-primary", "fingerprint": "3b59435b3211a9df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba44ffb1d2d04cec", "level": "note", "message": {"text": "Unused endpoint: USE /prize-images"}, "properties": {"repobilityId": "24002f4bbb37a38e", "scanner": "scanner-primary", "fingerprint": "ba44ffb1d2d04cec", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55f21a73fa2a83d2", "level": "note", "message": {"text": "Unused endpoint: POST /exit"}, "properties": {"repobilityId": "b20a480d0900d05f", "scanner": "scanner-primary", "fingerprint": "55f21a73fa2a83d2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d57a5fe4e8ba834d", "level": "note", "message": {"text": "Unused endpoint: POST /create-wallet"}, "properties": {"repobilityId": "0244833eaf82018a", "scanner": "scanner-primary", "fingerprint": "d57a5fe4e8ba834d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ce982210c81785c5", "level": "note", "message": {"text": "Unused endpoint: POST /recover-from-phrase"}, "properties": {"repobilityId": "ef4597848fa8e797", "scanner": "scanner-primary", "fingerprint": "ce982210c81785c5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "5adab8c253451fc8", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-afc064028ae39ea9", "level": "note", "message": {"text": "Unused endpoint: GET /history"}, "properties": {"repobilityId": "d2d8c4925e9d62f2", "scanner": "scanner-primary", "fingerprint": "afc064028ae39ea9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bdcae47b43f751d9", "level": "note", "message": {"text": "Unused endpoint: GET /vapid-public-key"}, "properties": {"repobilityId": "1aa6ecc18680183d", "scanner": "scanner-primary", "fingerprint": "bdcae47b43f751d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-365f0986d17746b8", "level": "note", "message": {"text": "Unused endpoint: POST /subscribe"}, "properties": {"repobilityId": "7a98932bd80804fb", "scanner": "scanner-primary", "fingerprint": "365f0986d17746b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "775e817dfc7fb372", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ef6dd1315a3338b", "level": "note", "message": {"text": "Unused endpoint: GET /current-message"}, "properties": {"repobilityId": "783b812f23c20beb", "scanner": "scanner-primary", "fingerprint": "1ef6dd1315a3338b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d315efa0f1b0f8fb", "level": "note", "message": {"text": "Unused endpoint: GET /inbox"}, "properties": {"repobilityId": "50812384f4b06922", "scanner": "scanner-primary", "fingerprint": "d315efa0f1b0f8fb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a641ecf39e8431f9", "level": "note", "message": {"text": "Unused endpoint: POST /react"}, "properties": {"repobilityId": "46067ad40c0f027e", "scanner": "scanner-primary", "fingerprint": "a641ecf39e8431f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd8dc4599ec52a08", "level": "note", "message": {"text": "Unused endpoint: GET /stats"}, "properties": {"repobilityId": "2b622439b84f24b8", "scanner": "scanner-primary", "fingerprint": "cd8dc4599ec52a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2120e295b7fc217c", "level": "note", "message": {"text": "Unused endpoint: GET /debug-push"}, "properties": {"repobilityId": "57c9c7ebd436b40c", "scanner": "scanner-primary", "fingerprint": "2120e295b7fc217c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-af00171afc55225a", "level": "note", "message": {"text": "Unused endpoint: GET /holders"}, "properties": {"repobilityId": "18c0f2130bf18ad3", "scanner": "scanner-primary", "fingerprint": "af00171afc55225a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-078755a1d3f6c729", "level": "note", "message": {"text": "Unused endpoint: GET /multilevel"}, "properties": {"repobilityId": "2bf5fdbc2acbddc4", "scanner": "scanner-primary", "fingerprint": "078755a1d3f6c729", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6e10ffd7f0cecdf1", "level": "note", "message": {"text": "Unused endpoint: POST /send-message"}, "properties": {"repobilityId": "eb8830ef2c3e2efb", "scanner": "scanner-primary", "fingerprint": "6e10ffd7f0cecdf1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e934dba02d2877a1", "level": "note", "message": {"text": "Unused endpoint: GET /messages"}, "properties": {"repobilityId": "71f4c0fbc4d455db", "scanner": "scanner-primary", "fingerprint": "e934dba02d2877a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-094415b878a0fad0", "level": "note", "message": {"text": "Unused endpoint: GET /reactions-summary"}, "properties": {"repobilityId": "d358d7c74898fae2", "scanner": "scanner-primary", "fingerprint": "094415b878a0fad0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b732547b209572e8", "level": "note", "message": {"text": "Unused endpoint: GET /event-sessions"}, "properties": {"repobilityId": "f68a1a2f63a06289", "scanner": "scanner-primary", "fingerprint": "b732547b209572e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d7bc7e80a429daad", "level": "note", "message": {"text": "Unused endpoint: GET /peak-hours"}, "properties": {"repobilityId": "3d36777f6ba17c5b", "scanner": "scanner-primary", "fingerprint": "d7bc7e80a429daad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e03a6de6e7f5fe8", "level": "note", "message": {"text": "Unused endpoint: GET /funnel"}, "properties": {"repobilityId": "07cb3611e4a20516", "scanner": "scanner-primary", "fingerprint": "3e03a6de6e7f5fe8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e567912e1835772", "level": "note", "message": {"text": "Unused endpoint: GET /segments"}, "properties": {"repobilityId": "076db352c9f20fd1", "scanner": "scanner-primary", "fingerprint": "4e567912e1835772", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3f7819037dd5c100", "level": "note", "message": {"text": "Unused endpoint: GET /hourly"}, "properties": {"repobilityId": "42f72a9f137c9530", "scanner": "scanner-primary", "fingerprint": "3f7819037dd5c100", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f1d4a03ddcfbd438", "level": "note", "message": {"text": "Unused endpoint: GET /message-stats"}, "properties": {"repobilityId": "d38d2ea8dffd742c", "scanner": "scanner-primary", "fingerprint": "f1d4a03ddcfbd438", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0ddbc8f66d3e2056", "level": "note", "message": {"text": "Unused endpoint: GET /report-data"}, "properties": {"repobilityId": "61c8c826f1c22264", "scanner": "scanner-primary", "fingerprint": "0ddbc8f66d3e2056", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2edb56c67bd4f621", "level": "note", "message": {"text": "Unused endpoint: GET /inspect-wallet/:address"}, "properties": {"repobilityId": "3d58692764c9b6e6", "scanner": "scanner-primary", "fingerprint": "2edb56c67bd4f621", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e41cf8e94598cb93", "level": "note", "message": {"text": "Unused endpoint: GET /polygon-balance"}, "properties": {"repobilityId": "b6589bc0310c5e21", "scanner": "scanner-primary", "fingerprint": "e41cf8e94598cb93", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0d4b15309bc1c224", "level": "note", "message": {"text": "Unused endpoint: GET /pending-mints"}, "properties": {"repobilityId": "02863a5a0e0d2c57", "scanner": "scanner-primary", "fingerprint": "0d4b15309bc1c224", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-549722626b5e35eb", "level": "note", "message": {"text": "Unused endpoint: POST /reconcile-mints"}, "properties": {"repobilityId": "88fc25182dbd2608", "scanner": "scanner-primary", "fingerprint": "549722626b5e35eb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7acc4e80fcca7ae4", "level": "note", "message": {"text": "Unused endpoint: POST /mints/:id/approve"}, "properties": {"repobilityId": "f1394d7710bf0571", "scanner": "scanner-primary", "fingerprint": "7acc4e80fcca7ae4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f617ab86bb6aa98f", "level": "note", "message": {"text": "Unused endpoint: POST /mints/:id/reject"}, "properties": {"repobilityId": "fd2525ff95c52132", "scanner": "scanner-primary", "fingerprint": "f617ab86bb6aa98f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}