Skip to content
QuantumScanPublic scan report

Repository

quantumscan-io/scanner-core

Scanned on Jul 1, 2026

100

Risk score/ 100

Critical risk

Summary

Análise Heurística (IA indisponível) — 62 ocorrências detectadas: ECDSA, DSA, liboqs (Open Quantum Safe) — entropy audit required, MD5, Ed25519 / EdDSA….

Critical

1

High

57

Medium

4

Low

0

Top findings

  • CriticalCWE-328MD5

    .github/ISSUE_TEMPLATE/suggest_pattern.yml:28

    SHA3-256 or SHA-256

    Raw evidence
    - Weak hash/cipher (MD5/SHA-1/DES/RC4) — classically weak
  • HighCWE-327ECDSA

    .github/ISSUE_TEMPLATE/false_positive.yml:16

    ML-DSA (CRYSTALS-Dilithium) or SLH-DSA (SPHINCS+)

    Raw evidence
    placeholder: ecdsa-keygen
  • HighCWE-327DSA

    .github/ISSUE_TEMPLATE/suggest_pattern.yml:11

    ML-DSA (CRYSTALS-Dilithium)

    Raw evidence
    like ML-KEM/Kyber/Dilithium/Falcon/SLH-DSA).
  • Highliboqs (Open Quantum Safe) — entropy audit required

    .github/ISSUE_TEMPLATE/suggest_pattern.yml:17

    Mandate OQS_randombytes() for ALL key generation (it sources from OpenSSL's CSPRNG). Audit every call to OQS_KEM_*/OQS_SIG_* key generation and trace the entropy path. Never mix rand()/Math.random() in the same translation unit as liboqs keygen.

    Raw evidence
    placeholder: "e.g. Falcon-512 signature verification (liboqs binding)"
  • HighCWE-327DSA

    .github/ISSUE_TEMPLATE/suggest_pattern.yml:26

    ML-DSA (CRYSTALS-Dilithium)

    Raw evidence
    - Classical asymmetric crypto (RSA/DSA/DH) — quantum-vulnerable

+ 57 more findings in the full report

Scan your own repository

Free. Results in ~90 seconds. CBOM + DORA/NIS2 PDF included.

Start a free scan