live · scanning repos
Scanrepo
github.com
github.com / jspdown

jspdown/code-review-annotator

Kotlin·38 files·commit 1e64a57·scanned 30m ago·cached ✓
8/100
SAFE
No malicious patterns found. Repo signals are consistent with a legitimate project.
verdict accurate?
threat-state: safelive

FINDINGS ░▒▓

infoSuspicious file in repoExecutable file (gradlew.bat) in repositorygradlew.bat+2
warningSingle-commit repositoryThe repository has only one commit. This is common for generated or throwaway malware repos.+3

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

2 files scanned @ 1e64a57 | 9/25/2026 | heuristic scan — always review manually

risk by category
code execution0
network & exfiltration0
file system access0
obfuscation0
supply chain5
owasp / injection0
telemetry
files 2/38rules hit 2engine v6commit 1e64a57

github

jspdown/code-review-annotator

A code review annotator for IntelliJ

Kotlin
5
5
190d
38 files
2 scanned(5%)
1e64a57

architecture░▒▓

No architecture graph available. This usually happens when the repo contains no scannable JS/TS/Python files or only a single file was analyzed.

SAFE (8/100) — jspdown/code-review-annotator — ScanRepo