realvuln v1.0
Dashboard Methodology Dataset Findings Roadmap GitHub ↗
Scanner deep-dive

Snyk Code by Snyk ↗

Rule-Based SAST · pattern+flow · scored on 25/26 repositories. Strict scoring (unfinished repos counted as misses).

18.0
F3 (strict)
18.8
F2 (strict)
17.2%
Recall (strict)
29.9%
Precision
25/26
Repos scored
Model
Free
Total cost
Avg latency
§

Per-repository breakdown

Each bar shows true positives, false positives, and misses on one repository; bar length is proportional to that repo's labeled vulnerabilities. Ranked by F2.

True positiveFalse positiveMissed (FN)
insecure-web60 F2 · 56%
intentionally-vulnerable-python-application57 F2 · 57%
pythonssti50 F2 · 50%
pygoat38 F2 · 40%
dvblab38 F2 · 36%
lets-be-bad-guys38 F2 · 33%
damn-vulnerable-flask-application30 F2 · 27%
dsvw29 F2 · 26%
vulnerable-flask-app26 F2 · 24%
djangoat20 F2 · 18%
extremely-vulnerable-flask-app18 F2 · 16%
vulnerable-api17 F2 · 14%
python-insecure-app14 F2 · 12%
vulpy14 F2 · 12%
threatbyte13 F2 · 12%
vfapi12 F2 · 11%
vulnpy12 F2 · 10%
dsvpwa11 F2 · 9%
vulnerable-python-apps10 F2 · 9%
owasp-web-playground9 F2 · 14%
dvpwa6 F2 · 5%
flask-xss4 F2 · 3%
damn-vulnerable-graphql-application0 F2 · 0%
vampi0 F2 · 0%
vulnerable-tornado-app0 F2 · 0%
RepositoryTPFPFNRecall %F2
insecure-web51455.659.5
intentionally-vulnerable-python-application43357.157.1
pythonssti11150.050.0
pygoat31654640.338.4
dvblab8101436.437.7
lets-be-bad-guys821633.337.7
damn-vulnerable-flask-application421126.730.3
dsvw762025.928.9
vulnerable-flask-app581623.825.8
djangoat9174118.019.9
extremely-vulnerable-flask-app532715.618.4
vulnerable-api211214.316.9
python-insecure-app12712.514.3
vulpy7135012.314.1
threatbyte352311.513.4
vfapi13811.112.5
vulnpy837010.312.4
dsvpwa34299.411.1
vulnerable-python-apps29209.110.1
owasp-web-playground41142414.38.7
dvpwa10214.55.6
flask-xss11293.34.1
damn-vulnerable-graphql-application05360.00.0
vampi03150.00.0
vulnerable-tornado-app00140.00.0
§

Detection by severity

SeverityTPFPFNRecall %
Critical3005236.6
High40321615.6
Medium46122616.9
Low40636.0
§

Detection by vulnerability class

CWE familyTPFPFNRecall %
Code Injection / RFI90564.3
Insecure Deserialization90852.9
Open Redirect30350.0
XML External Entities32442.9
SQL Injection1403230.4
Security Misconfiguration902427.3
Command / OS Injection411225.0
Cross-Site Scripting1906123.8
Hardcoded Credentials1314622.0
Path Traversal501920.8
Other29017114.5
Server-Side Request Forgery302112.5
Missing Authentication / Authorization00460.0
Broken Access Control / IDOR00240.0
Denial of Service00200.0
Sensitive Data Exposure00550.0
HTTP Header Injection0020.0
XPath Injection0040.0
§

Cost

Free
Total cost
0
Python LOC scanned
0
Successful runs

← Back to the leaderboard