https://github.com/open-webui/open-webui
· scanned 2026-06-05 04:50 UTC (6 hours, 13 minutes ago)
· 10 languages
893 findings (223 legacy + 670 scanner) 11/13 scanners ran 33rd percentile · Python · large (100-500K LoC)
Last scanned 6 hours, 13 minutes ago · v2 · 558 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
92.0 | 0.15 | 13.80 |
practices_score |
89.0 | 0.15 | 13.35 |
code_quality |
45.0 | 0.10 | 4.50 |
| Overall | 1.00 | 69.4 |
Showing 506 of 558 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
backend/open_webui/retrieval/vector/dbs/valkey.py:656
qualitylegacy
backend/open_webui/models/users.py:336
qualitylegacy
backend/open_webui/utils/oauth.py:1635
qualitylegacy
backend/open_webui/utils/auth.py:488
qualitylegacy
backend/open_webui/utils/misc.py:646
qualitylegacy
backend/open_webui/routers/auths.py:1364
qualitylegacy
backend/open_webui/routers/scim.py:592
qualitylegacy
backend/open_webui/models/files.py:279
qualitylegacy
backend/open_webui/retrieval/web/utils.py:207
qualitylegacy
backend/open_webui/routers/knowledge.py:609
qualitylegacy
backend/open_webui/tools/knowledge_fs.py:380
qualitylegacy
backend/open_webui/utils/misc.py:639
qualitylegacy
backend/open_webui/constants.py:42
credential_exposurelegacy
Dockerfile:98
dockerlegacy
src/routes/auth/+page.svelte:183
authlegacy
backend/open_webui/constants.py:42
secrets
backend/open_webui/retrieval/vector/dbs/oracle23ai.py:12
secrets
backend/open_webui/retrieval/vector/dbs/oracle23ai.py:18
secrets
backend/open_webui/retrieval/vector/dbs/oracle23ai.py:22
secrets
backend/open_webui/routers/chats.py:515
authlegacy
backend/open_webui/routers/knowledge.py:625
authlegacy
backend/open_webui/routers/pipelines.py:410
authlegacy
backend/open_webui/routers/pipelines.py:451
authlegacy
backend/open_webui/routers/users.py:481
authlegacy
backend/open_webui/main.py:2296
authlegacy
backend/open_webui/main.py:2313
authlegacy
backend/open_webui/routers/knowledge.py:438
authlegacy
backend/open_webui/routers/memories.py:282
authlegacy
backend/open_webui/routers/pipelines.py:492
authlegacy
backend/open_webui/retrieval/web/main.py:32
qualitylegacy
backend/open_webui/retrieval/web/firecrawl.py:68
qualitylegacy
backend/open_webui/retrieval/loaders/external_document.py:45
qualitylegacy
backend/open_webui/utils/asgi_middleware.py:99
qualitylegacy
backend/open_webui/utils/rate_limit.py:97
qualitylegacy
backend/open_webui/utils/rate_limit.py:88
qualitylegacy
backend/open_webui/utils/rate_limit.py:81
qualitylegacy
backend/open_webui/socket/utils.py:178
qualitylegacy
backend/open_webui/socket/utils.py:172
qualitylegacy
backend/open_webui/utils/rate_limit.py:124
qualitylegacy
backend/open_webui/utils/rate_limit.py:96
qualitylegacy
backend/open_webui/utils/rate_limit.py:102
qualitylegacy
backend/open_webui/utils/rate_limit.py:80
qualitylegacy
backend/open_webui/storage/provider.py:175
qualitylegacy
backend/open_webui/storage/provider.py:165
qualitylegacy
backend/open_webui/utils/rate_limit.py:71
qualitylegacy
backend/open_webui/utils/rate_limit.py:73
qualitylegacy
backend/open_webui/utils/rate_limit.py:69
qualitylegacy
backend/open_webui/storage/provider.py:166
qualitylegacy
backend/open_webui/utils/rate_limit.py:59
qualitylegacy
backend/open_webui/utils/rate_limit.py:61
qualitylegacy
backend/open_webui/utils/rate_limit.py:57
qualitylegacy
backend/open_webui/utils/rate_limit.py:67
qualitylegacy
backend/open_webui/utils/rate_limit.py:55
qualitylegacy
backend/open_webui/socket/utils.py:291
qualitylegacy
backend/open_webui/socket/utils.py:279
qualitylegacy
backend/open_webui/utils/rate_limit.py:76
qualitylegacy
backend/open_webui/socket/utils.py:278
qualitylegacy
backend/open_webui/storage/provider.py:148
qualitylegacy
backend/open_webui/utils/redis.py:188
qualitylegacy
.github/workflows/backend.yaml:30
dependencylegacy
.github/workflows/docker.yaml:70
dependencylegacy
.github/workflows/release-pypi.yml:19
dependencylegacy
.github/workflows/release.yml:24
dependencylegacy
.github/workflows/frontend.yaml:53
dependencylegacy
.github/workflows/frontend.yaml:26
dependencylegacy
.github/workflows/docker.yaml:173
dependencylegacy
.github/workflows/release.yml:66
dependencylegacy
.github/workflows/release-pypi.yml:24
dependencylegacy
.github/workflows/frontend.yaml:54
dependencylegacy
.github/workflows/frontend.yaml:27
dependencylegacy
.github/workflows/backend.yaml:31
dependencylegacy
.github/workflows/release-pypi.yml:27
dependencylegacy
.github/workflows/docker.yaml:136
dependencylegacy
.github/workflows/release.yml:56
dependencylegacy
.github/workflows/release-pypi.yml:36
dependencylegacy
Dockerfile:46
dependencylegacy
.pre-commit-config.yaml:2
dependencylegacy
src/lib/components/admin/Users/Groups/Permissions.svelte:389
authlegacy
Dockerfile:168
dockerlegacy
backend/open_webui/utils/redis.py:188
integritysync-io-in-asyncperformance
backend/open_webui/utils/plugin.py:233
owaspexec_used
backend/open_webui/utils/mcp/client.py:51
owasptls_verify_false
backend/open_webui/main.py:1528
authlegacy
backend/open_webui/main.py:2322
authlegacy
backend/open_webui/main.py:2327
authlegacy
backend/open_webui/main.py:2560
authlegacy
backend/open_webui/main.py:2546
authlegacy
backend/open_webui/main.py:2746
authlegacy
backend/open_webui/main.py:1538
authlegacy
backend/open_webui/main.py:2345
authlegacy
backend/open_webui/main.py:2313
authlegacy
backend/open_webui/main.py:2553
authlegacy
backend/open_webui/routers/calendar.py:316
authlegacy
backend/open_webui/routers/calendar.py:85
authlegacy
backend/open_webui/main.py:2367
authlegacy
backend/open_webui/main.py:2568
authlegacy
backend/open_webui/routers/calendar.py:269
authlegacy
backend/open_webui/routers/calendar.py:281
authlegacy
backend/open_webui/routers/openai.py:569
authlegacy
backend/open_webui/routers/openai.py:570
authlegacy
backend/open_webui/routers/calendar.py:262
authlegacy
backend/open_webui/routers/calendar.py:293
authlegacy
backend/open_webui/utils/filter.py:29
error_handlinglegacy
backend/open_webui/retrieval/web/main.py:32
error_handlinglegacy
backend/open_webui/retrieval/loaders/external_document.py:45
error_handlinglegacy
backend/open_webui/socket/utils.py:54
qualitylegacy
backend/open_webui/socket/utils.py:19
qualitylegacy
backend/open_webui/functions.py:147
qualitylegacy
backend/open_webui/models/feedbacks.py:210
qualitylegacy
backend/open_webui/utils/access_control/__init__.py:70
qualitylegacy
backend/open_webui/models/models.py:275
qualitylegacy
backend/open_webui/models/notes.py:160
qualitylegacy
backend/open_webui/models/prompts.py:291
qualitylegacy
backend/open_webui/models/skills.py:220
qualitylegacy
backend/open_webui/env.py:421
qualitylegacy
backend/open_webui/env.py:353
qualitylegacy
backend/open_webui/env.py:141
qualitylegacy
backend/open_webui/env.py:55
qualitylegacy
backend/open_webui/config.py:717
qualitylegacy
backend/open_webui/config.py:909
qualitylegacy
backend/open_webui/config.py:899
qualitylegacy
backend/open_webui/config.py:889
qualitylegacy
backend/open_webui/config.py:879
qualitylegacy
backend/open_webui/config.py:866
qualitylegacy
backend/open_webui/config.py:856
qualitylegacy
backend/open_webui/config.py:846
qualitylegacy
backend/open_webui/config.py:832
qualitylegacy
backend/open_webui/config.py:822
qualitylegacy
backend/open_webui/config.py:812
qualitylegacy
backend/open_webui/config.py:802
qualitylegacy
backend/open_webui/config.py:703
qualitylegacy
backend/open_webui/config.py:693
qualitylegacy
backend/open_webui/config.py:683
qualitylegacy
backend/open_webui/config.py:673
qualitylegacy
backend/open_webui/config.py:1563
qualitylegacy
backend/open_webui/config.py:468
qualitylegacy
backend/open_webui/__init__.py:60
qualitylegacy
contribution_stats.py:59
qualitylegacy
contribution_stats.py:16
qualitylegacy
backend/requirements-min.txt:21
dependencylegacy
backend/requirements-min.txt:22
dependencylegacy
backend/requirements-min.txt:20
dependencylegacy
backend/requirements-min.txt:59
dependencylegacy
backend/requirements-min.txt:12
dependencylegacy
backend/requirements-min.txt:46
dependencylegacy
backend/requirements-min.txt:57
dependencylegacy
backend/requirements-min.txt:37
dependencylegacy
backend/open_webui/utils/mcp/client.py:28
cryptolegacy
backend/open_webui/models/tools.py:148
qualitylegacy
backend/open_webui/models/tags.py:75
qualitylegacy
backend/open_webui/models/memories.py:68
qualitylegacy
src/routes/+layout.svelte:190
authlegacy
src/lib/components/chat/XTerminal.svelte:55
authlegacy
Dockerfile:41
dockerlegacy
src/lib/components/workspace/Prompts/PromptEditor.svelte:659
qualitylegacy
src/lib/components/chat/FileNav/FilePreview.svelte:111
qualitylegacy
src/lib/components/layout/Sidebar.svelte:496
qualitylegacy
.well-known/security.txt
qualitylegacy
static/robots.txt
qualitylegacy
.github/workflows/release-pypi.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:73
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:76
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:79
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:87
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:103
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:114
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:194
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:198
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:207
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:261
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:264
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:271
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-pypi.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docker.yaml
supply-chaingithub-actionsleast-privilege
.dockerignore
dockerlegacy
backend/open_webui/utils/logger.py:44
qualitylegacy
backend/open_webui/retrieval/vector/dbs/opensearch.py:162
qualitylegacy
backend/open_webui/constants.py:21
qualitylegacy
docker-compose.yaml:10
dockerlegacy
src/lib/apis/functions/index.ts:94
qualitylegacy
src/lib/apis/functions/index.ts:32
qualitylegacy
src/lib/apis/functions/index.ts:14
qualitylegacy
src/lib/apis/functions/index.ts:13
qualitylegacy
src/lib/apis/folders/index.ts:35
qualitylegacy
src/lib/apis/folders/index.ts:18
qualitylegacy
src/lib/apis/files/index.ts:164
qualitylegacy
src/lib/apis/files/index.ts:128
qualitylegacy
src/lib/apis/files/index.ts:21
qualitylegacy
src/lib/apis/evaluations/index.ts:295
qualitylegacy
src/lib/apis/evaluations/index.ts:41
qualitylegacy
src/lib/apis/evaluations/index.ts:5
qualitylegacy
src/lib/apis/configs/index.ts:13
qualitylegacy
src/lib/apis/channels/index.ts:338
qualitylegacy
src/lib/apis/channels/index.ts:152
qualitylegacy
src/lib/apis/channels/index.ts:146
qualitylegacy
src/lib/apis/calendar/index.ts:92
qualitylegacy
src/lib/apis/calendar/index.ts:68
qualitylegacy
src/lib/apis/automations/index.ts:63
qualitylegacy
src/lib/apis/auths/index.ts:5
qualitylegacy
src/lib/apis/audio/index.ts:71
qualitylegacy
backend/open_webui/routers/users.py:535
qualitylegacy
backend/open_webui/routers/users.py:88
qualitylegacy
backend/open_webui/routers/tools.py:328
qualitylegacy
backend/open_webui/routers/tools.py:176
qualitylegacy
backend/open_webui/routers/prompts.py:48
qualitylegacy
backend/open_webui/retrieval/vector/dbs/qdrant_multitenancy.py:8
qualitylegacy
backend/open_webui/retrieval/vector/dbs/pgvector.py:29
qualitylegacy
backend/open_webui/retrieval/vector/dbs/opensearch.py:32
qualitylegacy
backend/open_webui/retrieval/vector/dbs/milvus_multitenancy.py:10
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
static/robots.txt
qualitylegacy
src/lib/utils/_template_old.ts:1
qualitylegacy
Dockerfile:27
supply-chaindockerpinned-dependencies
Dockerfile:46
supply-chaindockerpinned-dependencies
.github/workflows/release.yml:56
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:66
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-pypi.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:70
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:136
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker.yaml:173
supply-chaingithub-actionspinned-dependencies
Showing first 300 of 506. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/eece5801-31e4-4d8a-b69e-8e16dd5dfc24/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/eece5801-31e4-4d8a-b69e-8e16dd5dfc24/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.