Scan timing: clone 4.59s · analysis 2.56s · 24.8 MB · GitHub API rate-limit (preflight)
https://github.com/microsoft/markitdown
· scanned 2026-06-04 04:10 UTC (1 day, 9 hours ago)
· 10 languages
223 findings (115 legacy + 108 scanner) 69th percentile · Python · small (2-20K LoC) Scanner says 89 (lower by 12)
Last scanned 1 day, 9 hours ago · v2 · 169 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
55.0 | 0.15 | 8.25 |
security_score |
97.7 | 0.25 | 24.43 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
80.0 | 0.15 | 12.00 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
43.6 | 0.10 | 4.36 |
| Overall | 1.00 | 77.3 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
packages/markitdown/src/markitdown/converters/_ll…:22
packages/markitdown/src/markitdown/converters/_im…:110
packages/markitdown-ocr/src/markitdown_ocr/_xlsx_…:211
packages/markitdown-ocr/src/markitdown_ocr/_pptx_…:121
packages/markitdown-ocr/src/markitdown_ocr/_docx_…:155
packages/markitdown-mcp/src/markitdown_mcp/__main…:129
packages/markitdown/src/markitdown/converter_util…:150
packages/markitdown/src/markitdown/converters/_pp…:262
packages/markitdown/src/markitdown/converters/_do…:133
packages/markitdown/src/markitdown/converters/_im…:112
packages/markitdown/src/markitdown/converters/_pd…:576
packages/markitdown/src/markitdown/converters/_rs…:176
This page is publicly accessible at:
https://repobility.com/scan/dbdaf599-dde3-40fb-aea4-0a5672c27966/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/dbdaf599-dde3-40fb-aea4-0a5672c27966/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.