Scan timing: clone 4.51s · analysis 16.06s · 21.7 MB · GitHub API rate-limit (preflight)
https://github.com/getlago/lago-api
· scanned 2026-06-05 12:59 UTC (5 days, 7 hours ago)
· 10 languages
233 raw signals (105 security + 128 graph) 11/13 scanners ran
Last scanned 5 days, 7 hours ago · v2 · 84 actionable findings from 2 signal sources. 85 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
91.0 | 0.15 | 13.65 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 67.7 |
Showing 60 of 84 actionable findings. 169 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
app/jobs/clock/terminate_ended_subscriptions_job.rb:9app/models/daily_usage.rb:15app/queries/customers_query.rb:76app/models/concerns/organizations/authentication_methods.rb:7
config/i18n-tasks.yml:110
db/seeds/01_base.rb:27, 30, 37, 45 (4 hits)config/routes.rb:202
config/routes.rb:199
config/routes.rb:200
config/routes.rb:201
config/routes.rb:216
config/routes.rb:203
config/routes.rb:217
config/routes.rb:97
config/routes.rb:182
config/routes.rb:174
Dockerfile:9, 32 (2 hits)Dockerfile.dev:9app/models/webhook.rb:47
app/controllers/api/v1/organizations_controller.rb:37
Dockerfile.dev:15
CI/CD securitycontainers
Dockerfile:17
CI/CD securitycontainers
.github/workflows/release.yml:35, 42, 47, 58, 105, 112, 115, 151 (9 hits).github/workflows/internal-build.yml:21, 29, 44 (5 hits).github/workflows/migrations-test.yml:46, 51 (4 hits).github/workflows/front-compatibility.yml:41 (2 hits).github/workflows/linters.yml:19 (2 hits).github/workflows/spec.yml:71 (2 hits).github/workflows/front-compatibility.yml:28, 34, 49 (6 hits).github/workflows/release.yml:31, 78, 97 (6 hits).github/workflows/linters.yml:15 (2 hits).github/workflows/migrations-test.yml:44 (2 hits).github/workflows/spec.yml:69 (2 hits).github/workflows/internal-build.yml:18config/routes.rb:202
config/routes.rb:200
config/routes.rb:201
config/routes.rb:209
config/routes.rb:207
config/routes.rb:203
config/routes.rb:208
config/routes.rb:42
config/routes.rb:56
config/routes.rb:44
config/routes.rb:57
config/routes.rb:46
config/routes.rb:13
config/routes.rb:58
config/routes.rb:60
config/routes.rb:59
config/routes.rb:61
Dockerfile:42
CI/CD securitycontainers
Dockerfile.dev:10
CI/CD securitycontainers
Dockerfile:33
CI/CD securitycontainers
Dockerfile:54
CI/CD securitycontainers
Dockerfile:16, 37 (2 hits).well-known/security.txt
public/robots.txt
config/application.rb:34
Weak hash
.dockerignore
CI/CD securitycontainers
Dockerfile:17, 38 (2 hits)Dockerfile.dev:15Dockerfile.dev:15
CI/CD securitycontainers
app/controllers/api/v1/subscriptions/entitlements_controller.rb:20, 55 (2 hits)app/controllers/api/v1/analytics/invoiced_usages_controller.rb:7app/controllers/api/v1/analytics/mrrs_controller.rb:7app/controllers/api/v1/analytics/overdue_balances_controller.rb:7app/controllers/api/v1/plans/entitlements_controller.rb:66app/controllers/api/v1/subscriptions/alerts_controller.rb:31app/controllers/api/v1/subscriptions/charges/filters_controller.rb:6app/controllers/api/v1/subscriptions/charges_controller.rb:8public/robots.txt
Dockerfile:3
containersPinned dependencies
Dockerfile:9, 32 (2 hits)
This page is publicly accessible at:
https://repobility.com/scan/d5bbf7bb-a3db-4b3d-8722-27b2b726c0b2/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/d5bbf7bb-a3db-4b3d-8722-27b2b726c0b2/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.