realvuln v1.0
Dashboard Methodology Dataset Findings Roadmap GitHub ↗
Scanner deep-dive

SonarQube by SonarSource ↗

Rule-Based SAST · community · scored on 26/26 repositories. Strict scoring (unfinished repos counted as misses).

6.9
F3 (strict)
7.7
F2 (strict)
6.3%
Recall (strict)
61.1%
Precision
26/26
Repos scored
Model
Free
Total cost
Avg latency
§

Per-repository breakdown

Each bar shows true positives, false positives, and misses on one repository; bar length is proportional to that repo's labeled vulnerabilities. Ranked by F2.

True positiveFalse positiveMissed (FN)
lets-be-bad-guys38 F2 · 33%
insecure-web38 F2 · 33%
python-app23 F2 · 20%
vulnerable-python-apps20 F2 · 18%
pygoat17 F2 · 14%
extremely-vulnerable-flask-app15 F2 · 12%
vulpy10 F2 · 9%
vulnpy8 F2 · 6%
damn-vulnerable-flask-application0 F2 · 0%
damn-vulnerable-graphql-application0 F2 · 0%
djangoat0 F2 · 0%
dsvpwa0 F2 · 0%
dsvw0 F2 · 0%
dvblab0 F2 · 0%
dvpwa0 F2 · 0%
flask-xss0 F2 · 0%
intentionally-vulnerable-python-application0 F2 · 0%
owasp-web-playground0 F2 · 0%
python-insecure-app0 F2 · 0%
pythonssti0 F2 · 0%
threatbyte0 F2 · 0%
vampi0 F2 · 0%
vfapi0 F2 · 0%
vulnerable-api0 F2 · 0%
vulnerable-flask-app0 F2 · 0%
vulnerable-tornado-app0 F2 · 0%
RepositoryTPFPFNRecall %F2
lets-be-bad-guys811633.338.1
insecure-web31633.337.5
python-app431620.023.0
vulnerable-python-apps461818.220.4
pygoat11116614.316.7
extremely-vulnerable-flask-app422812.514.9
vulpy54528.810.5
vulnpy50736.47.9
damn-vulnerable-flask-application00150.00.0
damn-vulnerable-graphql-application00360.00.0
djangoat00500.00.0
dsvpwa00320.00.0
dsvw00270.00.0
dvblab00220.00.0
dvpwa00220.00.0
flask-xss00300.00.0
intentionally-vulnerable-python-application0070.00.0
owasp-web-playground00280.00.0
python-insecure-app0080.00.0
pythonssti0020.00.0
threatbyte00260.00.0
vampi00150.00.0
vfapi0090.00.0
vulnerable-api00140.00.0
vulnerable-flask-app00210.00.0
vulnerable-tornado-app00140.00.0
§

Detection by severity

SeverityTPFPFNRecall %
Critical1007611.6
High1402505.3
Medium2012597.2
Low00680.0
§

Detection by vulnerability class

CWE familyTPFPFNRecall %
Code Injection / RFI401028.6
Hardcoded Credentials1414723.0
Path Traversal502119.2
Command / OS Injection301417.6
Open Redirect10516.7
XML External Entities10712.5
Cross-Site Scripting1007212.2
Insecure Deserialization201710.5
Server-Side Request Forgery20228.3
SQL Injection10462.1
Other102050.5
Missing Authentication / Authorization00470.0
Broken Access Control / IDOR00240.0
Denial of Service00200.0
Security Misconfiguration00330.0
Sensitive Data Exposure00570.0
HTTP Header Injection0020.0
XPath Injection0040.0
§

Cost

Free
Total cost
0
Python LOC scanned
0
Successful runs

← Back to the leaderboard