Current repository readingScanned Jul 25, 2026, 3:57 AM UTC

find-sec-bugs Codebase Valuation

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

View find-sec-bugs/find-sec-bugs on GitHub
Open share card
CodeValuation.com
RepoWorth
github.com/find-sec-bugs

find-sec-bugs

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

RepoWorth$7,894Current measured development value · 4.5 active build days
Rebuild complexity95.11/100Profile: Complex
537K code tokens1.2K source filesJava primary language
Scanned Jul 25, 2026Public GitHub repositorycodevaluation.com/repoworth/find-sec-bugs
Authored code537K tokens · 74,275 source lines
Complexity95.11/100 · Complex
Primary stackJava
Scan coverage100% · Content scan
RepoWorth development valuation

One valuation, with the evidence behind it.

RepoWorth models the current development value represented by the visible repository evidence. It does not include ideation, intellectual property, business value, product discovery, or sale price.

RepoWorthCurrent measured development value
$7,894

Modeled range $6,315 to $9,473

4.5 active build days36.2 engineering hours453K implementation tokens
Repository evidenceMeasured at the scanned commit
537K tokens

74,275 source lines across 1,222 authored files

524 test files889 dependencies100% scan coverage
Repository evidence

Building the historical and contribution view.

The headline RepoWorth and measured source facts are ready. Comparable history, accepted changes, and badge evidence will appear here as enrichment finishes.

Repository contributors

Top contributors.

Ranked from the public GitHub contributor evidence available at the latest scan. This table describes measured repository activity, not ownership or original authorship.

RankContributorContributionsShare of top groupLatest measured activity
#1slovdahl@slovdahl5100.0%Current GitHub contributor snapshot
About find-sec-bugs

What the public repository appears to contain.

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

bytecodecode-analysiscwefindbugshacktoberfestjavaowaspsecuritysecurity-auditstatic-analysistaint-analysis
License
LGPL-3.0
Default branch
master
GitHub stars
2,432
Forks
484
Last public push
Mar 26, 2026
Repository state
Active public repository
Detected language profile2.4MB authored source
Java84.55%
CSS11.73%
XML1.57%
Kotlin1.09%
JavaScript0.99%
Shell0.04%
GRADLE0.03%
Source files1,222
Test files524
Manifests9
Dependencies889
Measured technical evidence

A fuller view of what the scanner found.

These values come from the same immutable repository scan as the headline RepoWorth. They stay tied to the scanned commit so the reading can be inspected against one exact source state.

Maintainability signal66/100

Established based on deterministic repository structure and complexity signals.

Production source285.6K tokens

First-party implementation tokens eligible for the modeled code-scale input.

Test evidence251.4K tokens

524 detected test files contribute separately from production code.

Configuration and infrastructure0 tokens

9 manifests and 0 workspace boundaries were detected.

Documentation65K tokens

87 documentation files remain visible as a distinct enablement signal.

Integration surface5,208 signals

889 dependency declarations and 4,091 public-interface signals were measured.

Repository structure12 levels deep

0 large files and 3,750 branch signals add structural context.

Excluded from authored evidence0 files

5 generated files were identified. Ignored and generated material does not inflate RepoWorth.

Measured repository distinctions

Repository evidence highlights.

Each highlight records a measured characteristic of the same repository scan used for this RepoWorth report.

architecture

Interface builder

At least 500 deterministic public interface signals were measured in source.

architecture

Integration surface

At least 1,000 deterministic integration signals were measured in source.

quality

Verification depth

At least 20 percent of measured source tokens are in test paths.

architecture

Dependency ecosystem

At least 500 dependency declarations were measured across supported manifests.

quality

Test fortress

At least 35 percent of measured source tokens are in detected test paths.

Technical effort profile

What makes this repository harder to rebuild.

Code scale, branching, dependencies, languages, structure, and visible test evidence shape the implementation and verification effort represented by this repository.

Code scaleHigh

Measured from the current source archive.

ComplexityHigh

Derived from branch density, dependencies, languages, and code scale.

VerificationHigh

Measures visible test code relative to the source corpus.

Development effort composition

Source volume alone does not explain the work.

This view separates authored evidence from the implementation, integration, verification, and engineering oversight represented by the current repository.

Reading boundary: These are modeled development inputs for the visible code. They do not include product discovery, company value, private systems, or commercial outcomes.

Weighted authored evidence453KProduction, tests, configuration, and documentation
Estimated implementation output453KImplementation, retries, integration, and verification
Engineering oversight36.2 hoursOrientation, integration, tests, and review
Active build time4.5 daysModeled effort represented by the current source state
Evidence boundary

What this valuation includes.

CodeValuation.com counted supported authored source on commit 90447f7e39e529c31cf098ebade0a755b944dd91, measured deterministic repository signals, then estimated implementation, rework, testing, integration, and engineering oversight.

Included

Supported first-party source, tests, configuration, manifests, repository structure, dependency signals, and framework boundaries.

Excluded

Common generated and vendored files, build output, dependencies, lockfiles, minified assets, binaries, media, and private systems outside this repository.

Not claimed

Ideation, intellectual-property rights, security posture, production reliability, company value, sale price, revenue, user value, proprietary data, or the cost of discovering the original product.

This is a modeled current development valuation for the repository's visible code at a specific commit. It reflects code volume, implementation output, complexity, and engineering oversight. It is not a business valuation, investment appraisal, security review, or estimate of sale price, ideation, intellectual property, revenue, users, brand, proprietary data, undocumented domain knowledge, or private infrastructure.

Check another repository

Run RepoWorth on your own codebase.

Enter a public GitHub URL to create a current repository reading.

No sign-up for public repositories. Private repositories require a free trial. Evaluated in real time directly from GitHub. Code is never stored. Derived measurements and valuation history are saved.