https://github.com/dubinc/dub
· scanned 2026-05-16 12:50 UTC (1 day, 7 hours ago)
· 10 languages
831 findings (12 legacy + 819 scanner) 2/10 scanners ran 16th percentile · Typescript · large (100-500K LoC)
Last scanned 3 days, 1 hour ago · v1 · 823 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
20.0 | 0.20 | 4.00 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 64.8 |
Showing 13 of 823 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/playwright.yaml:36
secrets
.github/workflows/playwright.yaml:58
secrets
apps/web/playwright/partners/auth.setup.ts:6
secrets
apps/web/playwright/seed.ts:11
secrets
apps/web/playwright/workspaces/auth.setup.ts:6
secrets
apps/web/app/app.dub.co/(auth)/oauth/authorize/scopes-requested.tsx:44
owaspdangerous_innerhtml
apps/web/app/app.dub.co/(dashboard)/[slug]/(ee)/settings/logs/[logId]/page-client.tsx:222
owaspdangerous_innerhtml
apps/web/ui/domains/domain-configuration.tsx:129
owaspdangerous_innerhtml
apps/web/ui/guides/markdown.tsx:105
owaspdangerous_innerhtml
apps/web/ui/postbacks/postback-event-details-sheet.tsx:99
owaspdangerous_innerhtml
apps/web/ui/support/code-block.tsx:198
owaspdangerous_innerhtml
apps/web/ui/webhooks/webhook-event-details-sheet.tsx:99
owaspdangerous_innerhtml
packages/ui/src/form.tsx:69
owaspdangerous_innerhtml
This page is publicly accessible at:
https://repobility.com/scan/e8971222-160d-42f1-967c-5e0c4aa69c35/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/e8971222-160d-42f1-967c-5e0c4aa69c35/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.