live · scanning repos
Scanrepo
github.com
github.com / jealous-sound

jealous-sound/azerothcore-wotlk-coa

C++·12978 files·commit bb7de17·scanned 1h ago·cached ✓
47/100
SUSPICIOUS
Obfuscation or dynamic code paths detected. Intent unclear — review before running anything.
verdict accurate?
Created 18 days ago
Created 18 days ago
1% file coverage
CLI tool detected
threat-state: suspiciouslive

FINDINGS ░▒▓

infoSuspicious files are not reachable from entry pointsFlagged files exist but are not imported by any entry point. They may be dead code, tests, or attack payloads triggered by another mechanism.+2
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.apps/coa-gameplay-test/scenarios/ascension-reward-items.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.apps/coa-gameplay-test/scenarios/barbarian-audit-1051-1069-3730-3904-raid-auras.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.apps/coa-gameplay-test/scenarios/barbarian-audit-1124-1292-2022-stat-passives.json+4
warningHigh-entropy string literalsFound 6 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.apps/EnumUtils/enumutils_describe.py+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.apps/ci/ci-pending-changelogs.ts+3
warningHigh-entropy string literalsFound 9 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.apps/coa-bugreport/relay.py+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.apps/coa-bugreport/relay.py+3
infoSuspicious file in repoExecutable file (extractor.bat) in repositoryapps/extractor/extractor.bat+2
infoSuspicious file in repoExecutable file (extractor_es.bat) in repositoryapps/extractor/extractor_es.bat+2
infoSuspicious file in repoVery large source file (751KB) — could contain obfuscated payloaddata/coa-world/baseline.json+2
warningHardcoded secret/credentialAPI keys, passwords, or tokens hardcoded in source code. Should be in environment variables.apps/coa-bugreport/relay.py
API = SERVICE_URL + "/v1/reports"
DEFAULT_API_KEY = "coa_zRatxUHShOn-HEkoreKGME6sd3DdMG7eKTTKlj2JCK4"
WEB = f"https://github.com/{REPOSITORY}/issues/"
KEY = re.compile(r"[1-9][0-9]{0,9}-[0-9a-f]{16,48...
+3

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

120 files scanned @ bb7de17 | 9/25/2026 | heuristic scan — always review manually

risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain12
owasp / injection3
telemetry
files 120/12978rules hit 12engine v6commit bb7de17

github

jealous-sound/azerothcore-wotlk-coa

Conquest of AzerothCore

C++
197
128
18d
12978 files
120 scanned(1%)
bb7de17

architecture░▒▓

entry (0) flagged (9) pkg (42)
95 nodes · 171 edgesscroll to zoom · click node to jump to finding