realvuln v1.0
Dashboard Methodology Dataset Findings Roadmap GitHub ↗
Scanner deep-dive

Kolega.Dev by Kolega ↗

Security-Specialized · v0.0.1 · scored on 26/26 repositories. Strict scoring (unfinished repos counted as misses).

73.0
F3 (strict)
66.8
F2 (strict)
80.5%
Recall (strict)
39.8%
Precision
26/26
Repos scored
Model
Free
Total cost
Avg latency
§

Per-repository breakdown

Each bar shows true positives, false positives, and misses on one repository; bar length is proportional to that repo's labeled vulnerabilities. Ranked by F2.

True positiveFalse positiveMissed (FN)
extremely-vulnerable-flask-app87 F2 · 100%
dsvw83 F2 · 93%
lets-be-bad-guys83 F2 · 96%
vulnerable-tornado-app79 F2 · 100%
vampi78 F2 · 80%
dvpwa75 F2 · 86%
owasp-web-playground74 F2 · 93%
dsvpwa74 F2 · 88%
vulpy72 F2 · 82%
flask-xss71 F2 · 87%
vulnerable-api71 F2 · 93%
threatbyte70 F2 · 88%
vulnerable-flask-app69 F2 · 90%
vfapi68 F2 · 100%
insecure-web66 F2 · 100%
dvblab64 F2 · 86%
vulnpy62 F2 · 63%
python-insecure-app61 F2 · 88%
vulnerable-python-apps60 F2 · 73%
intentionally-vulnerable-python-application59 F2 · 86%
pygoat59 F2 · 68%
damn-vulnerable-flask-application58 F2 · 80%
damn-vulnerable-graphql-application56 F2 · 67%
djangoat54 F2 · 72%
pythonssti50 F2 · 100%
python-app49 F2 · 65%
RepositoryTPFPFNRecall %F2
extremely-vulnerable-flask-app32240100.087.0
dsvw2517292.683.3
lets-be-bad-guys2320195.882.7
vulnerable-tornado-app14190100.078.7
vampi125380.077.9
dvpwa1920386.474.8
owasp-web-playground2637292.974.3
dsvpwa2834487.573.7
vulpy47531082.571.6
flask-xss2638486.770.7
vulnerable-api1323192.970.7
threatbyte2337388.570.1
vulnerable-flask-app1934290.569.3
vfapi9210100.068.2
insecure-web9230100.066.2
dvblab1941386.464.2
vulnpy49322962.862.3
python-insecure-app718187.561.4
vulnerable-python-apps1629672.760.2
intentionally-vulnerable-python-application617185.758.8
pygoat52842567.558.6
damn-vulnerable-flask-application1232380.057.7
damn-vulnerable-graphql-application24461266.756.1
djangoat36941472.054.5
pythonssti2100100.050.0
python-app1340765.048.9
§

Detection by severity

SeverityTPFPFNRecall %
Critical7631088.4
High20785778.4
Medium22245779.6
Low5611282.4
§

Detection by vulnerability class

CWE familyTPFPFNRecall %
Command / OS Injection1710100.0
XML External Entities810100.0
HTTP Header Injection200100.0
Cross-Site Scripting773593.9
Hardcoded Credentials571493.4
Code Injection / RFI130192.9
Security Misconfiguration300390.9
SQL Injection403785.1
Insecure Deserialization161384.2
Other16634080.6
Server-Side Request Forgery190579.2
Sensitive Data Exposure4401377.2
XPath Injection30175.0
Path Traversal183869.2
Open Redirect40266.7
Broken Access Control / IDOR150962.5
Missing Authentication / Authorization2801959.6
Denial of Service401620.0
§

Cost

Free
Total cost
0
Python LOC scanned
0
Successful runs

← Back to the leaderboard