Scan timing: clone 4.37s · analysis 27.96s · 12.4 MB · GitHub API rate-limit (preflight)
https://github.com/yt-dlp/yt-dlp
· scanned 2026-06-04 22:00 UTC (15 hours, 26 minutes ago)
· 10 languages
667 findings (295 legacy + 372 scanner) 3rd percentile · Python · large (100-500K LoC) Scanner says 79 (lower by 29)
Last scanned 15 hours, 25 minutes ago · v2 · 481 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
0.0 | 0.25 | 0.00 |
testing_score |
43.0 | 0.20 | 8.60 |
documentation_score |
93.6 | 0.15 | 14.04 |
practices_score |
91.0 | 0.15 | 13.65 |
code_quality |
45.0 | 0.10 | 4.50 |
| Overall | 1.00 | 49.8 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
.well-known/security.txt
yt_dlp/networking/websocket.py:18
yt_dlp/networking/_helper.py:163
yt_dlp/extractor/motherless.py:169
devscripts/tomlparse.py:129
devscripts/make_lazy_extractors.py:81
yt_dlp/networking/__init__.py:37
yt_dlp/networking/__init__.py:30
yt_dlp/networking/__init__.py:23
yt_dlp/networking/_requests.py:244
yt_dlp/downloader/fc2.py:27
yt_dlp/downloader/niconico.py:79
yt_dlp/extractor/gofile.py:65
yt_dlp/extractor/dropbox.py:62
yt_dlp/extractor/ciscowebex.py:42
This page is publicly accessible at:
https://repobility.com/scan/fe8748da-1f2f-4f59-9f1b-dbc2d86d5b99/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fe8748da-1f2f-4f59-9f1b-dbc2d86d5b99/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.