https://github.com/strapi/strapi.git
· scanned 2026-05-19 15:50 UTC (2 weeks, 2 days ago)
· 10 languages
1433 findings (129 legacy + 1304 scanner) 11/13 scanners ran 79th percentile · Typescript · huge (>500K LoC) Scanner says 60 (higher by 28)
Last scanned 2 weeks, 2 days ago · v2 · 781 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
81.0 | 0.15 | 12.15 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 88.2 |
Showing 358 of 781 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/changeFreeze.yml:19
dependencylegacy
.github/workflows/pr-reviewer.yml:25
dependencylegacy
.github/workflows/docs-flag-notification.yml:17
dependencylegacy
packages/cli/create-strapi-app/src/utils/database.ts:167
secrets
packages/plugins/graphql/server/src/services/constants.ts:45
secrets
packages/core/database/src/query/query-builder.ts:240
qualitylegacy
packages/core/content-type-builder/admin/src/components/DataManager/undoRedo.ts:79
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/ApiTokens/EditView/reducer.ts:80
qualitylegacy
packages/core/database/src/query/query-builder.ts:457
qualitylegacy
.github/workflows/issues_handleLabel.yml:199
dependencylegacy
.github/workflows/issues_handleLabel.yml:191
dependencylegacy
.github/workflows/issues_handleLabel.yml:172
dependencylegacy
.github/workflows/issues_handleLabel.yml:162
dependencylegacy
.github/workflows/issues_handleLabel.yml:144
dependencylegacy
.github/workflows/issues_handleLabel.yml:134
dependencylegacy
.github/workflows/issues_handleLabel.yml:112
dependencylegacy
.github/workflows/issues_handleLabel.yml:102
dependencylegacy
.github/workflows/issues_handleLabel.yml:75
dependencylegacy
.github/workflows/issues_handleLabel.yml:65
dependencylegacy
.github/workflows/issues_handleLabel.yml:42
dependencylegacy
.github/workflows/issues_handleLabel.yml:22
dependencylegacy
.github/workflows/pr-reviewer.yml:18
dependencylegacy
.github/workflows/caniuse.yml:17
dependencylegacy
.github/workflows/publish-release.yml:35
dependencylegacy
.github/workflows/adminBundleSize.yml:24
dependencylegacy
.github/workflows/clean-up-pr-caches.yml:15
dependencylegacy
.github/workflows/publish-release.yml:30
dependencylegacy
.github/workflows/publish-release.yml:41
dependencylegacy
.github/workflows/adminBundleSize.yml:25
dependencylegacy
.github/workflows/close_stale_issues.yml:14
dependencylegacy
.github/workflows/caniuse.yml:25
dependencylegacy
.github/workflows/adminBundleSize.yml:35
dependencylegacy
.github/workflows/changeFreeze.yml:30
dependencylegacy
.github/workflows/changeFreeze.yml:16
dependencylegacy
packages/core/core/src/loaders/admin.ts:13
prototype_pollutionlegacy
packages/core/content-manager/server/src/services/components.ts:110
xsslegacy
packages/core/content-manager/server/src/homepage/services/homepage.ts:32
xsslegacy
examples/complex/scripts/bench-compare.js:490
xsslegacy
packages/core/content-manager/server/src/controllers/validation/index.ts:26
qualitylegacy
packages/core/content-manager/admin/src/utils/validation.ts:263
qualitylegacy
packages/core/content-manager/admin/src/pages/EditView/components/FormInputs/UID.tsx:66
qualitylegacy
examples/complex/scripts/db-postgres.js:61
qualitylegacy
examples/complex/scripts/db-mysql.js:54
qualitylegacy
examples/complex/scripts/db-mariadb.js:53
qualitylegacy
packages/core/content-manager/server/src/services/metrics.ts:31
error_handlinglegacy
packages/core/content-manager/admin/src/preview/utils/previewScript.ts:266
error_handlinglegacy
packages/cli/create-strapi-app/src/utils/usage.ts:74
error_handlinglegacy
packages/core/core/src/services/server/http-server.ts:6
qualitylegacy
packages/core/content-type-builder/admin/src/components/FormModal/attributes/ConditionForm.tsx:110
qualitylegacy
packages/core/admin/admin/src/utils/users.ts:52
qualitylegacy
examples/complex/scripts/db-utils.js:60
qualitylegacy
examples/complex/scripts/setup-v4-project.js:205
qualitylegacy
packages/core/content-type-builder/admin/src/components/AIChat/hooks/useFigmaUpload.ts:60
authlegacy
packages/core/content-type-builder/admin/src/components/AIChat/hooks/useFigmaUpload.ts:48
authlegacy
packages/core/admin/admin/src/utils/getFetchClient.ts:202
authlegacy
packages/core/admin/admin/src/utils/getFetchClient.ts:75
authlegacy
packages/core/admin/admin/src/utils/getFetchClient.ts:72
authlegacy
packages/core/admin/admin/src/reducer.ts:80
authlegacy
packages/core/admin/admin/src/reducer.ts:32
authlegacy
.github/workflows/caniuse.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:22
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:65
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:75
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:102
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:112
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:134
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:144
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:162
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:172
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:191
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_handleLabel.yml:199
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-reviewer.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/find_duplicate_issue.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/needs-qa-checklist.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/issues_dailyCron.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/contributor-doc.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/caniuse.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/pr-reviewer.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/find_duplicate_issue.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/needs-qa-checklist.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-npm.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/contributor-doc.yml
supply-chaingithub-actionsleast-privilege
packages/core/admin/admin/src/components/GuidedTour/Steps/Step.tsx:265
owaspdangerous_innerhtml
packages/core/content-manager/admin/src/pages/EditView/components/FormInputs/Wysiwyg/PreviewWysiwyg.tsx:29
owaspdangerous_innerhtml
packages/providers/upload-aws-s3/src/index.ts:27
owaspweak_hash
packages/plugins/users-permissions/documentation/content-api.yaml
securityports
packages/plugins/users-permissions/documentation/content-api.yaml
securityports
packages/plugins/users-permissions/documentation/content-api.yaml
securityports
packages/plugins/users-permissions/documentation/content-api.yaml
securityports
packages/plugins/users-permissions/documentation/content-api.yaml
securityports
packages/plugins/users-permissions/documentation/content-api.yaml
securityports
packages/core/admin/server/src/content-types/transfer-token.ts:9
qualitylegacy
packages/core/admin/server/src/content-types/transfer-token.ts:8
qualitylegacy
packages/core/admin/server/src/content-types/transfer-token-permission.ts:15
qualitylegacy
packages/core/admin/server/src/content-types/transfer-token-permission.ts:9
qualitylegacy
packages/core/admin/server/src/content-types/api-token.ts:10
qualitylegacy
packages/core/admin/server/src/content-types/api-token-permission.ts:9
qualitylegacy
packages/core/admin/ee/admin/src/pages/SettingsPage/pages/SingleSignOnPage.tsx:76
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/Webhooks/ListPage.tsx:79
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/Users/utils/validation.ts:23
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/Users/components/NewUserForm.tsx:255
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/Users/EditPage.tsx:193
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/TransferTokens/ListView.tsx:109
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/TransferTokens/EditView.tsx:301
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/TransferTokens/EditView.tsx:112
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/Roles/ListPage.tsx:167
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/Roles/EditPage.tsx:97
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/Roles/EditPage.tsx:84
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/PurchaseSingleSignOn.tsx:42
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/PurchaseSingleSignOn.tsx:20
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/PurchaseContentHistory.tsx:21
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/ApiTokens/ListView.tsx:60
qualitylegacy
packages/core/admin/admin/src/pages/Settings/pages/ApiTokens/EditView/EditViewPage.tsx:114
qualitylegacy
packages/core/admin/admin/src/pages/NotFoundPage.tsx:9
qualitylegacy
packages/core/admin/admin/src/pages/Home/components/FreeTrialWelcomeModal.tsx:8
qualitylegacy
packages/core/admin/admin/src/pages/Auth/components/ResetPassword.tsx:127
qualitylegacy
packages/core/admin/admin/src/pages/Auth/components/ResetPassword.tsx:32
qualitylegacy
packages/core/admin/admin/src/pages/Auth/components/Oops.tsx:38
qualitylegacy
jest-preset.unit.js:19
qualitylegacy
.github/actions/community-pr-triage/src/modes/weekly-report.ts:41
qualitylegacy
examples/complex/public/robots.txt
qualitylegacy
.github/workflows/clean-up-pr-caches.yml:15
supply-chaingithub-actionspinned-dependencies
.github/workflows/caniuse.yml:17
supply-chaingithub-actionspinned-dependencies
.github/workflows/close_stale_issues.yml:14
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-reviewer.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/find_duplicate_issue.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/needs-qa-checklist.yml:20
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-npm.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-npm.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/diff_prs.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/watch_stale_issues.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/community-label.yml:45
supply-chaingithub-actionspinned-dependencies
.github/workflows/community-label.yml:77
supply-chaingithub-actionspinned-dependencies
.github/workflows/community-label.yml:108
supply-chaingithub-actionspinned-dependencies
.github/workflows/contributor-doc.yml:30
supply-chaingithub-actionspinned-dependencies
package.json
supply-chainnpminstall-scripts
Showing first 300 of 358. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/fd0d49e3-fbea-455c-9358-68c783fa4c4a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fd0d49e3-fbea-455c-9358-68c783fa4c4a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.