realvuln v1.0
Dashboard Methodology Dataset Findings Roadmap GitHub ↗
Scanner deep-dive

Kolega Enterprise by Kolega ↗

Security-Specialized · enterprise-v1 · scored on 26/26 repositories. Strict scoring (unfinished repos counted as misses).

92.4
F3 (strict)
89.7
F2 (strict)
95.3%
Recall (strict)
72.7%
Precision
26/26
Repos scored
Model
Free
Total cost
Avg latency
§

Per-repository breakdown

Each bar shows true positives, false positives, and misses on one repository; bar length is proportional to that repo's labeled vulnerabilities. Ranked by F2.

True positiveFalse positiveMissed (FN)
pythonssti100 F2 · 100%
flask-xss98 F2 · 100%
insecure-web98 F2 · 100%
vulnpy97 F2 · 100%
extremely-vulnerable-flask-app97 F2 · 100%
dvblab91 F2 · 100%
vulnerable-tornado-app91 F2 · 100%
damn-vulnerable-graphql-application90 F2 · 92%
dvpwa90 F2 · 100%
python-app90 F2 · 100%
djangoat90 F2 · 96%
damn-vulnerable-flask-application90 F2 · 93%
intentionally-vulnerable-python-application90 F2 · 100%
python-insecure-app90 F2 · 88%
dsvw90 F2 · 89%
vulnerable-api89 F2 · 93%
vulpy89 F2 · 95%
lets-be-bad-guys88 F2 · 92%
vulnerable-flask-app88 F2 · 90%
vampi87 F2 · 100%
pygoat86 F2 · 96%
dsvpwa86 F2 · 88%
vfapi85 F2 · 89%
owasp-web-playground84 F2 · 96%
threatbyte84 F2 · 92%
vulnerable-python-apps78 F2 · 82%
RepositoryTPFPFNRecall %F2
pythonssti200100.0100.0
flask-xss3030100.098.0
insecure-web910100.097.8
vulnpy78110100.097.3
extremely-vulnerable-flask-app3250100.097.0
dvblab22110100.090.9
vulnerable-tornado-app1470100.090.9
damn-vulnerable-graphql-application336391.790.2
dvpwa22120100.090.2
python-app20110100.090.1
djangoat4819296.089.9
damn-vulnerable-flask-application144193.389.7
intentionally-vulnerable-python-application740100.089.7
python-insecure-app70187.589.7
dsvw242388.989.6
vulnerable-api134192.989.0
vulpy5422394.788.8
lets-be-bad-guys227291.788.0
vulnerable-flask-app195290.588.0
vampi15110100.087.2
pygoat7448396.186.0
dsvpwa287487.585.9
vfapi83188.985.1
owasp-web-playground2722196.483.9
threatbyte2415292.383.9
vulnerable-python-apps189481.878.3
§

Detection by severity

SeverityTPFPFNRecall %
Critical8600100.0
High25421096.2
Medium26111893.5
Low630592.6
§

Detection by vulnerability class

CWE familyTPFPFNRecall %
Code Injection / RFI1400100.0
Command / OS Injection1700100.0
Denial of Service2000100.0
Path Traversal2600100.0
Server-Side Request Forgery2400100.0
Insecure Deserialization1900100.0
Open Redirect600100.0
HTTP Header Injection200100.0
XPath Injection400100.0
Hardcoded Credentials600198.4
SQL Injection462197.9
Cross-Site Scripting801297.6
Security Misconfiguration320197.0
Other1970995.6
Broken Access Control / IDOR220291.7
XML External Entities70187.5
Sensitive Data Exposure490886.0
Missing Authentication / Authorization390883.0
§

Cost

Free
Total cost
0
Python LOC scanned
0
Successful runs

← Back to the leaderboard