https://github.com/steveg1983/wealthtracker-pro
· scanned 2026-06-16 00:23 UTC (2 months, 2 weeks ago)
214 raw signals (0 security + 214 graph)
Last scanned 2 months, 2 weeks ago · v1 · 130 actionable findings from 1 signal source. 84 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 91 of 130 actionable findings. 214 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/utils/errorMessages.ts:113, 114 (2 hits)repo-level (43 hits)apps/server/.github/workflows/labels.yml:15, 22, 29 (3 hits)wealthtracker-backend/.github/workflows/labels.yml:15, 22, 29 (3 hits).github/workflows/gitleaks.yml:23apps/server/.github/workflows/commitlint.yml:18apps/server/.github/workflows/danger.yml:18apps/server/.github/workflows/secrets-scan.yml:19wealthtracker-backend/.github/workflows/commitlint.yml:18wealthtracker-backend/.github/workflows/danger.yml:18src/components/GlobalSearch.tsx:85
Dangerous innerhtml
src/components/layout/AccessibilityImprovements.tsx:14
Dangerous innerhtml
src/components/LocalMerchantLogo.tsx:55
Dangerous innerhtml
src/components/MarkdownEditor.tsx:181
Dangerous innerhtml
src/components/MarkdownNote.tsx:54
Dangerous innerhtml
src/components/security/SafeHTML.tsx:41
Dangerous innerhtml
src/pages/Transactions.tsx:202
Direct innerhtml assignment
src/security/csrf-protection.ts:291
Local storage auth token
scripts/auto-fix-unused-vars.cjs:13
Node child process
scripts/build-web.mjs:2
Node child process
scripts/dr-restore-drill.mjs:22
Node child process
scripts/run-realtime-suite.mjs:4
Node child process
scripts/run-supabase-smoke.mjs:4
Node child process
scripts/verify-financial-safety.mjs:15
Node child process
scripts/verify-type-safety.mjs:18
Node child process
apps/server/.github/workflows/ci.yml:18, 21, 45, 48, 65, 67 (6 hits)wealthtracker-backend/.github/workflows/ci.yml:18, 21, 45, 48, 65, 67 (6 hits).github/workflows/handoff-snapshot.yml:18, 21, 51, 54 (4 hits).github/workflows/supabase-smoke.yml:13, 16, 49 (3 hits).github/workflows/dependency-audit.yml:26, 29 (2 hits).github/workflows/gitleaks.yml:18apps/server/.github/workflows/commitlint.yml:13apps/server/.github/workflows/danger.yml:13apps/server/package.json
LockfileReproducibilityGenerated repo pattern
packages/core/package.json
LockfileReproducibilityGenerated repo pattern
packages/utils/package.json
LockfileReproducibilityGenerated repo pattern
wealthtracker-backend/package.json
LockfileReproducibilityGenerated repo pattern
package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/ed352260-8247-4b8c-b14e-c2ded7615d43/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/ed352260-8247-4b8c-b14e-c2ded7615d43/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.