Generated
2026-10-04 11:14:18 UTC
FreeCAD Project Association
173
Total Addons
92.89
Avg Score
9,276
Files Analyzed
191
High Issues
734
Medium Issues
1,180,674
Downloads (Year)
Showing 0 of 0 addons
# Addon Version Label Score High Med Low Updated 1yr 1mo Files Git Ref Tag License Created
1 fasteners Some common fasteners and fastener tools for FreeCAD. ['Shai Seger'] 0.5.67 master 100 0 0 0 23 d 192,678 29,578 420 85 107 94 master V0.5.67-beta GPL-2.0-or-later 2015-06-18
2 ThreadProfile ThreadProfile object for creating internal/external threads ['TheMarkster'] 2.03 master 100 0 0 0 19 d 19,318 3,370 80 30 17 6 master LGPL-2.1 2019-07-22
3 CurvedShapes Create 3D shapes from 2D curves. ['Christi'] 1.00.15 master 100 0 0 0 4 mo 23,871 2,814 87 12 15 12 master LGPL-2.1 2019-06-11
4 FusedFilamentDesign PartDesign addon for FFF/FDM 3D-printing design ['rahix'] 0.26.360 release 100 0 0 0 1 mo 15,785 2,343 251 17 7 11 release v0.26.360 LGPL-2.1-or-later 2025-05-11
5 AddonManager Tool to install workbenches, macros, themes, etc. ['Jonathan Wiedemann', 'Kurt Kremitzki', 'Yorik van Havre', 'Chris Hennes'] 2026.9.26 main 100 0 0 0 7 d 22,260 2,280 19 28 30 111 main LGPL-2.1-or-later 2025-04-06
6 ThreadWorkbench Thread Workbench is a FreeCAD workbench for generating metric and inch threads ['ThreadWorkbench'] 0.3.1 master 100 0 0 0 3 mo 7,607 2,159 11 3 4 45 master version_change GPL-3.0-or-later 2026-05-30
7 SearchBar Adds a search bar widget for tools, document objects, and preferences ['Paul Ebbers'] 1.8.2 main 100 0 0 0 2 d 9,040 1,645 6 9 9 27 main CCOv1 2024-11-07
8 Silk NURBS Surface modeling tools focused on low degree and seam continuity ['edwardvmills'] 0.4.0 master 100 0 0 0 2 mo 11,647 1,073 96 5 16 43 master GPL-3.0-or-later 2017-05-20
9 dodo A set of commands and objects that help to speed-up the drawing of frames and pipelines. Py3/Qt5 port of flamingo. ['Riccardo Treu (oddtopus)'] 1.0.1 master 100 0 0 0 2 yr 4,839 733 31 20 29 18 master LGPLv3 2019-03-24
10 Behave-Dark-Colors A preference pack including GUI color information to extend the Behave Dark stylesheet ['Chrismettal'] 0.1.1 main 100 0 0 0 2 yr 4,738 553 11 2 4 0 main GPL-3.0-only 2022-01-30
11 Woods Collection of various wood materials. ['David Carter', 'Gregory Holmberg'] 1.1.0 master 100 0 0 0 9 mo 5,274 543 13 3 2 4 master v1.1.0 LGPL-2.1-or-later, CDLA-Sharing-1.0, CC-BY-SA-4.0 2025-06-26
12 Marz Parametric Guitar design workbench ['Frank Martinez'] 0.1.22 master 100 0 0 0 2 mo 4,504 528 134 7 26 67 master v0.1.22 GPL-3.0-or-later, LGPL-2.1-or-later 2020-04-05
13 Dracula Dracula dark theme for FreeCAD ['Eleanor Clifford'] 0.0.9 master 100 0 0 0 1 yr 4,572 505 38 9 5 0 master MIT 2021-03-07
14 Catppuccin Light / Dark theme and preference pack. ['cnvuls'] 1.0.0 Latest 100 0 0 0 5 mo 2,271 383 5 1 1 0 main MIT 2026-04-04
15 FileExplorerExt Integrated file system viewer. ['Frank David Martínez Muñoz'] 1.0.7 main 100 0 0 0 29 d 1,555 381 5 0 2 22 main v1.0.7 LGPL-3.0-or-later 2025-12-24
16 Supplemental-Materials Materials database that supplements the core materials. ['DavesRocketShop'] 1.0.2 Latest 100 0 0 0 1 mo 1,037 368 8 0 6 2 Latest LGPL-3.0-or-later, CC-BY-SA-4.0 2026-03-01
17 StandardBeams Workbench to create standard beam profiles of varying shapes. ['Morten Vajhøj'] 1.0.0 Latest 100 0 0 0 8 mo 3,062 352 6 0 1 56 main LGPL-2.1-or-later, CC-BY-SA-4.0 2026-01-14
18 SvgWorkbench FreeCAD Svg Workbench ['Frank David Martínez Muñoz'] 1.0.0.dev15 main 100 0 0 0 2 mo 2,671 328 12 1 3 71 main LGPL-3.0-or-later, LGPL-2.1-or-later 2025-02-07
19 Beltrami Workbench for designing Turbomachine blades. ['Michel Sabourin'] 1.3.3 main 100 0 0 0 5 mo 3,789 285 43 0 13 5 main 1.3.3 LGPL-2.1-or-later 2021-05-10
20 FeedsAndSpeeds CAM addon to help generate basic feeds and speeds for machining. ['Daniel Wood'] 0.6 master 100 0 0 0 10 mo 2,622 202 50 17 11 4 master LGPL-2.1-or-later 2020-04-10
21 BananaForScale Adds a banana for scale to FreeCAD. ['Fabio Tavernini'] 1.1.0 main 100 0 0 0 2 mo 872 169 8 0 1 3 main MIT, CC-BY-4.0, CC0-1.0 2026-07-04
22 Movie Workbench to create and animate the movie camera, create and play videos of animations ['F_Rosa'] 2026.08.23 master 100 0 0 0 1 mo 597 162 15 0 7 6 master LGPL-2.1-or-later 2022-12-12
23 Telemetry Help improve FreeCAD by sending basic metrics to the development team. ['The FreeCAD project association AISBL'] 1.0.7 main 100 0 0 0 21 d 1,992 125 13 6 4 9 main LGPL-2.1-or-later, CC-BY-4.0 2025-02-16
24 BrickFace Transform a planar face into a LEGO-compatible face (studs or sockets) from the Part Design Face Tools task panel. ['Jacques Hullu'] 0.2.1 main 100 0 0 0 1 mo 17 17 3 0 0 7 main MIT 2026-08-23
25 AddonManager Development branch of a tool to install workbenches, macros, themes, etc. ['Jonathan Wiedemann', 'Kurt Kremitzki', 'Yorik van Havre', 'Chris Hennes'] 2026.9.26dev development 100 0 0 0 7 d 0 0 19 28 30 111 dev LGPL-2.1-or-later 2025-04-06
26 Channels FreeCAD Channels - Connector to Blender ['Frank David Martínez Muñoz'] 0.1.0.dev4 main 100 0 0 0 6 mo 89 0 75 0 4 41 main LGPL-3.0-or-later 2025-04-11
27 FoamCut Foamcut workbench provide functionality to prepare job and generate Gcode for 4 or 5 axis cnc hotwire cutter. ['Andrew Shkolik (https://github.com/Shkolik)', 'Andrew Shkolik'] 0.2.0 main 100 0 0 0 2 mo 613 0 24 4 3 25 main LGPL-2.1-or-later 2024-01-12
28 FreecadDiscordPresence Shows FreeCAD Status on discord. ['Tzur Soffer'] 1.0.3 main 100 0 0 0 1 yr 0 0 20 0 3 4 main Version1.0.3 LGPL-2.1-or-later 2024-12-09
29 ImportNURBS An external workbench for add importer for 3dm> ['Keith Sloan'] 1.1 Beta master 100 0 0 0 6 mo 0 0 13 4 6 4 master LGPL-2.1 2020-03-23
30 InstrumentInput Use Bluetooth-connected measurement instruments such as calipers as input devices ['Steffen Vogel (stv0g)'] 0.3.1 main 100 0 0 0 4 mo 0 0 0 0 0 9 main Apache-2.0
31 Pyramids-and-Polyhedrons Create various polyhedrons in the Part workbench. ['Eddy Verlinden', 'PhoneDroid'] 0.2.2 Latest 100 0 0 0 6 mo 878 0 1 0 7 32 Latest GPL-3.0-or-later, CC-BY-SA-4.0, Unlicense 2025-09-14
32 Templater A workbench to gather some drafting related tools ['FBXL5'] 0.0.6 main 100 0 0 0 4 mo 264 0 0 0 0 10 main LGPL-3.0-or-later
33 TexturedObjImporter Import UV-mapped OBJ meshes with MTL and image textures. ['Marco Laffranchi'] 0.1.1 main 100 0 0 0 1 mo 0 0 0 0 0 8 main LGPL-2.1-or-later 2026-08-21
34 Vars FreeCAD Vars ['Frank David Martínez Muñoz'] 0.0.2.beta7 main 100 0 0 0 3 mo 0 0 20 2 1 42 main LGPL-3.0-or-later 2025-05-19
35 freecad-xr-workbench A Virtual Reality (OpenXR) workbench. View your models with VR goggles. ['Adrian Przekwas'] 1.0.2 main 100 0 0 0 1 mo 75 0 37 1 5 17 main LGPL-3.0-or-later 2023-07-29
36 toSketch Tools to help recreate models from STEP files. ['Keith Sloan'] 1.0.1 main 100 0 0 0 9 mo 2,755 0 21 8 4 14 main GPL-2.0-or-later 2021-01-02
37 yaml-workbench A FreeCAD addon that loads and manipulates objects via YAML files. ['MambiX Ltd.'] 0.1.4 FreeCAD ≥ v1.0 100 0 0 0 1 yr 0 0 12 2 3 23 master v0.1.4 LGPL-2.1-or-later 2017-11-26
38 sheetmetal A simple sheet metal tools workbench for FreeCAD. ['Shai Seger'] 0.8.24 master 99.9 0 0 1 4 d 115,711 18,421 345 118 91 36 master Last LGPL-2.1-or-later 2015-06-12
39 MakerWorkbench A mechatronic components system + optic components system ['David Muñoz'] 1.0.1 master 99.9 0 0 1 2 yr 3,172 347 52 6 13 60 master LGPL-3 2020-07-24
40 AssemblyCut Cut multiple PartDesign bodies with a single sketch. Auto-detects intersected bodies, supports reordering and per-body Pocket parameters. ['Cipa'] 1.2.0 main 99.9 0 0 1 2 mo 431 264 1 0 0 5 main LGPL-2.1-or-later 2026-07-18
41 Plot Tools to modify existing plots. ['Jose Luis Cercós Pita', 'PhoneDroid', 'hasecilu', 'looooo'] 2026.04.15 Latest 99.9 0 0 1 2 mo 0 0 17 0 12 20 Latest LGPL-2.1-or-later, CC-BY-SA-4.0 2018-09-22
42 Ratchet Workbench to quickly create ratchets. ['error on line 1'] 1.0.0 Latest 99.9 0 0 1 6 mo 0 0 5 0 1 27 main v1.0.0 LGPL-3.0-or-later 2022-08-13
43 Solar Workbench to manage solar analysis and configurations. ['Francisco Rosa'] 2026.08.22 Main 99.9 0 0 1 1 mo 0 0 26 4 4 11 main LGPL-2.1-or-later 2025-07-13
44 HexFill Fill any sketch with a honeycomb pattern in one click. Pick a sketch, choose the cell size, and HexFill builds the whole hexagonal grid for you - ready to Pocket into a lightweight perforated panel or Pad into a honeycomb solid. Manual or automatic sizing, edge trimming and a live 3D preview. Several closed regions in one sketch are filled at once. ['Clientik'] 1.2.5 main 99.8 0 0 2 2 mo 1,766 556 11 2 2 5 main v1.2.5 MIT 2026-06-11
45 CadbaseLibrary The workbench provides users with an easier way to work with components on the CADBase platform through the FreeCAD interface. Component modifications contain sets of files for various CAD systems. This workbench will work with data from the FreeCAD set, without the need to download documentation and data from other file sets. ['mnnxp'] 3.0.0 master 99.8 0 0 2 1 yr 1,844 24 8 0 2 13 master v3.0.0 LGPL-3.0-or-later 2023-02-10
46 Assembly2MuJoCo An addon for exporting FreeCAD builtin Assemblies to MuJoCo. ['Anes Benmerzoug'] 0.4.0 main 99.8 0 0 2 5 mo 87 0 34 2 9 27 main v0.4.0 LGPL-2.1-or-later 2025-04-19
47 CamScripts CamScripts ToolBit import or script creation and configure *every* step of FreeCAD CAM process. ['spanner888'] V0.0.5 2024/09/25 main 99.8 0 0 2 5 mo 494 0 4 4 2 14 main LGPL-2.1-or-later 2024-08-23
48 NikraDAP Multibody Planar Dynamics Workbench based on a DAP solver algorithm developed by P.E. Nikravesh. ['Lukas du Plessis'] 2.0-alpha main 99.8 0 0 2 4 yr 0 0 3 2 3 11 main GPL-3 2023-02-22
49 Design-Proof Proof-test your parametric CAD models by systematically varying dimensions and measuring regeneration success rates. ['Unai-Pz-de-A'] 0.1.3 Latest 99.7 0 0 3 5 mo 0 0 5 14 0 15 main v0.1.3 LGPL-2.1-or-later 2026-03-30
50 RotaryMoulder Design rotary cookie moulder drums. Wraps flat cookie outlines onto a cylindrical drum and cuts drafted cavities, with engraved or embossed text and shape details, roster (lattice) details, docker pins, cutting cups, and pattern replication around the drum. ['Mike Passchier'] 1.3.1 main 99.7 0 0 3 4 mo 0 0 0 0 0 4 main LGPL-2.1-or-later 2026-05-20
51 ShapeStrings Advanced tools for creating and manipulating ShapeStrings. ['Robert Massaioli'] 0.3.0 Main 99.6 0 0 4 2 mo 922 257 4 0 1 28 main v0.3.0 LGPL-2.1-or-later 2025-12-21
52 Motion-Control Link motion controller to an assembly using OPC UA. ['PhoneDroid', 'heissgetraenk'] 1.1.0 Latest 99.6 0 0 4 6 mo 0 0 0 0 6 13 Latest GPL-3.0-or-later 2025-09-25
53 freecad.gears A gear workbench for FreeCAD ['looooo'] 1.4.0 master 99.5 0 0 5 19 d 72,675 12,471 362 78 117 53 master GPL-3.0-or-later 2014-04-08
54 DFM Design for manufacturing workbench. Evaluate designs against manufacturing processes and associated rules. ['Ryan Kembrey'] 0.1.21 Latest 99.3 0 0 7 17 d 2,867 676 63 39 6 79 main LGPL-2.1-or-later 2025-08-03
55 BillOfMaterials A workbench to create Bill of Materials (BoM) independent of the assembly workbench of your choice. ['Paul Ebbers'] 1.3.3 main 99.2 0 0 8 5 d 7,994 1,073 34 4 4 36 main LGPL-3.0-or-later 2023-11-05
56 IDF Importer for IDF files. ['Milos Koutny', 'PhoneDroid'] 1.0.0 Latest 99 0 1 0 7 mo 0 0 1 2 0 12 Latest LGPL-2.1-or-later, CC-BY-SA-4.0 2026-03-07
57 Nodes Visual scripting workbench for FreeCAD ['Ronny Scharf-Wildenhain'] 0.1.36 main 99 0 1 0 2 yr 0 0 120 14 17 110 main LGPL-2.1-or-later 2022-08-10
58 Curves A collection of tools mainly dedicated to NURBS curves and surfaces modeling. ['Christophe Grellier'] 0.6.81 main 98.9 0 1 1 1 d 105,678 15,664 155 33 39 120 main LGPL-2.1-or-later, Apache-2.0 2016-08-06
59 free2ki Export your 3D models to VRML files, with correctly applied rotation and scaling, for use in KiCad as well as Blender. ['30350n'] 1.1.2 Latest 98.9 0 1 1 9 mo 282 0 59 0 4 6 freecad-addons v1.1.2 GPL-3.0-or-later 2022-01-09
60 Detessellate FreeCAD workbench of tools to reverse engineer meshes ['DesignWeaver3D'] 1.2.0 main 98.7 0 1 3 21 d 3,712 1,088 98 7 7 23 main LGPL-2.1-or-later 2025-11-22
61 WB_Organizer A workbench organizer widget for FreeCAD. Allows you to group your long list of workbenches into smaller meaningful groups. Allows you to rename some workbenches for better understanding or translation. Allows to show the workbench selector as tabbar. ['Palmstroemen'] 2024.1.29 main 98.6 0 0 14 3 yr 3,267 369 6 5 3 3 main LGPL-2.1-or-later 2024-01-26
62 FreeCAD-Beginner-Assistant Best practices modeling assistant for the Part and Sketcher workbench. ['Elizabeth Harasymiw', 'Aleksander Sadowski(https://github.com/alekssadowski95/FreeCAD-Beginner-Assistant)', 'Aleksander Sadowski'] 1.0 main 98.5 0 1 5 2 yr 253 18 18 6 5 37 main LGPL-2.1-or-later 2023-12-12
63 ToolSeek Type-to-find FreeCAD commands (command palette). Default shortcut: Ctrl+Space. ['therobdev'] 0.3.1 main 98.3 0 1 7 2 mo 0 0 5 2 1 15 main v0.3.1 LGPL-2.1-or-later, CC-BY-4.0 2026-08-11
64 stepParts Search the step.parts online catalog of open STEP CAD parts and insert results directly into the active document. ['Chris Bruner'] 0.1.1 main 98 0 2 0 2 mo 0 0 1 0 1 4 main v0.1.1 LGPL-2.1-or-later 2026-07-31
65 frame A workbench for beams and frames ['looooo'] 0.1.1 master 97.9 0 2 1 2 mo 5,198 717 27 11 6 26 master LGPL-2.1-or-later 2015-11-23
66 CarteGrid Generate and batch-export multiple variations of a parametric model, to whatever format FreeCAD can produce. Define a parameter grid over an App::VarSet, preview the resulting variations and their names, then export a chosen set of objects per variation. ['Marc Bresson'] 1.3.1 main 97.9 0 2 1 25 d 0 0 3 2 0 42 main MIT 2026-07-09
67 MnesarcoUtils A collection of tools mainly dedicated to scripting and experiments. ['Frank Martinez'] 0.2.16 main 97.8 0 2 2 6 mo 0 0 19 1 7 65 main GPL-3.0 2021-01-18
68 pyOpToolsWorkbench An optics ray-tracing workbench based on pyOpTools ['Ricardo Amézquita Orozco'] 0.0.5 master 97.8 0 2 2 4 d 0 0 26 4 6 81 master GPL-3.0-or-later 2017-07-06
69 Cables Electrical cables drawing tools workbench for FreeCAD. ['SargoDevel'] 0.3.7 master 97.7 0 2 3 2 mo 16,279 2,319 99 9 7 33 master v0.3.7 LGPL-3.0-or-later 2025-01-21
70 HistoryWorkbench Easy version control for FreeCAD: track document history and review changes using 3D and tree comparisons. ['Ephi Blanshey'] 0.2.0 release 97.7 0 1 13 13 d 1,349 612 155 4 4 320 release LGPL-2.1-or-later 2026-05-05
71 cadquery_module Build CadQuery models withing FreeCAD. ['Jeremy Wright'] 2.2.0 master 97.7 0 0 23 3 mo 464 0 151 5 44 11 master Apache-2.0 2014-11-22
72 freecad-wakatime A simple FreeCAD WakaTime extension. ['Pegoku'] 0.6.0 main 97.6 0 2 4 3 mo 0 0 4 2 7 6 main LGPL-2.1-or-later 2025-01-05
73 Ship Naval ship design (architecture, seakeeping, and ship resistance) ['Jose Luis Cercós Pita'] 2024.11.26 master 97.4 0 2 6 1 yr 1,043 148 58 6 29 71 master LGPL-2.1-or-later 2018-11-08
74 Quetzal A set of commands and objects that help to speed-up the drawing of frames and pipelines. Dodo successor. ['Edgar Robles', 'triplus', 'microelly', 'looo', 'Edgar J Robles', 'Riccardo Treu (oddtopus)'] 1.8.11 master 97.3 0 2 7 1 mo 8,826 964 34 20 29 28 master LGPL-3.0-or-later 2020-05-03
75 NeoRibbon Lightweight ribbon UI for FreeCAD 1.1+. Maps the active workbench toolbars into a compact top ribbon, hides classic toolbars while enabled, and restores them on disable. No external Python dependencies. ['Rob'] 0.3.6 master 97.3 0 2 7 1 mo 271 271 6 1 1 20 master LGPL-2.1-or-later, LGPL-2.1-or-later 2026-08-09
76 FrameForge FrameForge is dedicated for creating Frames and Beams, and apply operations (miter cuts, trim cuts) on these profiles. ['Vivien Henry'] 0.2.1 main 97 0 3 0 6 mo 11,210 1,143 38 37 13 25 main v0.2.1 LGPL-3.0-only 2024-10-07
77 ExplodedAssembly [] master 97 1 0 0 3 yr 4,425 635 140 24 26 4 master 2016-03-13
78 AirPlaneDesign A FreeCAD workbench dedicated to Airplane Design. ['FredsFactory'] 0.4.1 master 97 1 0 0 10 mo 5,190 597 118 9 22 19 master LGPL-2.1 2018-06-11
79 ProDarkThemePreferencePack ProDark preference pack including a stylesheet and othe GUI colour information for a complete ProDark experience ['turn211'] 1.0.0 main 97 1 0 0 3 yr 5,124 517 8 0 1 0 main GPL-2.0-or-later 2022-05-17
80 ArchTextures [] master 97 1 0 0 5 yr 2,919 415 35 23 15 23 master 2018-09-30
81 CommandPanel [] master 97 1 0 0 8 yr 0 0 3 1 5 10 master 2017-06-30
82 CubeMenu [] master 97 1 0 0 6 yr 0 0 6 1 0 8 master 2020-02-08
83 IconThemes [] master 97 1 0 0 6 yr 485 0 22 8 5 3 master 2016-10-10
84 Pyramids-and-Polyhedrons Create various polyhedrons in the Part workbench. ['Eddy Verlinden', 'PhoneDroid'] 0.2.2 Stable 97 1 0 0 6 mo 979 0 1 0 7 32 Stable v0.2.2 GPL-3.0-or-later, CC-BY-SA-4.0, Unlicense 2025-09-14
85 SelectorToolbar [] master 97 1 0 0 7 yr 0 0 8 3 4 2 master 2017-03-18
86 TabBar [] master 97 1 0 0 8 yr 0 0 8 1 3 2 master 2016-01-09
87 ToolbarStyle [] master 97 1 0 0 8 yr 0 0 3 0 0 3 master 2018-01-31
88 ose-piping [] master 97 1 0 0 4 yr 0 0 13 6 7 35 master 2018-02-17
89 pivy_trackers [] master 97 1 0 0 7 yr 0 0 23 6 6 61 master 2019-09-19
90 yaml-workbench A FreeCAD addon that loads and manipulates objects via YAML files. ['MambiX Ltd.'] 0.1.4 FreeCAD < v1.0 97 1 0 0 1 yr 0 0 12 2 3 23 v0.1.4 v0.1.4 LGPL-2.1-or-later 2017-11-26
91 MeshRemodel Workbench for remodeling and repairing mesh objects. ['Mark Ganson'] 1.12.0 master 96.9 0 3 1 28 d 7,664 1,590 35 0 8 10 master LGPL-2.1-or-later 2019-08-18
92 Defeaturing A set of tools to edit a Shape or a STEP model. ['Maui'] 1.3.2 master 96.9 1 0 1 4 mo 8,760 1,078 39 8 8 8 master AGPLv3.0 2018-07-02
93 Plot Tools to modify existing plots. ['Jose Luis Cercós Pita', 'PhoneDroid', 'hasecilu', 'looooo'] 2026.04.15 Stable 96.9 1 0 1 6 mo 2,035 326 17 0 12 20 Stable LGPL-2.1-or-later, CC-BY-SA-4.0 2018-09-22
94 dxf-library [] master 96.9 1 0 1 3 yr 2,194 242 73 4 38 4 master 2013-06-22
95 taack-plm-freecad This workbench contains tools to interact with Taack Plm Intranet server app you can find under the https://github.com/Taack/plm ['Adrien GUICHARD'] 2026.10.04 main 96.9 1 0 1 today 33 33 16 1 4 4 main LGPL-2.1-or-later 2023-02-09
96 Plot Tools to modify existing plots. ['Jose Luis Cercós Pita', 'PhoneDroid', 'hasecilu', 'looooo'] 2025.10.29 1.0.X 96.9 1 0 1 11 mo 0 0 17 0 12 23 2025.10.29 2025.10.29 LGPL-2.1-or-later, CC-BY-SA-4.0 2018-09-22
97 symbols_library [] master 96.9 1 0 1 5 mo 1,290 0 39 0 17 0 master 2015-04-21
98 addFC Additional tools for FreeCAD. ['Golodnikov Sergey'] 3.7.8 main 96.8 0 2 12 2 mo 11,795 926 52 1 6 21 main LGPL-2.1-or-later 2024-05-12
99 ConstraintDesign This addon adds a design workbench that is specially designed to be as flexible and stable as possible. ['drwho495'] beta-0.1 main 96.8 1 0 2 6 d 2,283 54 15 16 2 47 main LGPL-2.1-only 2025-04-13
100 Cubinets Visualize cabinet assemblies using parametric templates and generate cut lists. ['Vytautas Rimkevicius'] 0.1.0-demo Stable 96.8 1 0 2 6 mo 0 0 3 0 1 28 stable GPL-3.0-or-later 2026-02-20
101 Cubinets Visualize cabinet assemblies using parametric templates and generate cut lists. ['Vytautas Rimkevicius'] 0.1.0-demo Latest 96.8 1 0 2 6 mo 0 0 3 0 1 28 latest GPL-3.0-or-later 2026-02-20
102 Lithophane [] master 96.8 1 0 2 5 yr 234 0 37 15 10 37 master 2018-06-05
103 lattice2 Tools and arrays of all sorts and kinds, and local coordinate systems ['DeepSOIC'] 1.1 master 96.7 1 0 3 3 mo 13,086 1,301 84 34 14 73 master LGPL-2.0-or-later 2015-11-26
104 Motion-Control Link motion controller to an assembly using OPC UA. ['PhoneDroid', 'heissgetraenk'] 1.1.0 Stable 96.6 1 0 4 6 mo 0 0 0 0 6 13 Stable v1.1.0 GPL-3.0-or-later 2025-09-25
105 slic3r-tools [] master 96.3 1 0 7 7 yr 0 0 17 8 4 9 master 2019-05-08
106 BillOfMaterials A workbench to create Bill of Materials (BoM) independent of the assembly workbench of your choice. ['Paul Ebbers'] 1.3.3 Develop 96.2 1 0 8 5 d 0 0 34 4 4 36 Develop LGPL-3.0-or-later 2023-11-05
107 LCInterlocking Create interlocking parts for laser cutting or CNC milling ['execuc'] 1.5.1 master 96 1 1 0 10 mo 4,560 521 197 37 41 32 master 1.5.1 LGPL-2.1-or-later 2016-06-20
108 Plot Some tools to manipulate the FreeCAD plots ['Jose Luis Cercós Pita'] 2024.11.26 FreeCAD < 1.0 95.9 1 1 1 2 yr 0 0 17 0 12 16 2024.11.26 2024.11.26 LGPL-2.1-or-later 2018-09-22
109 InventorLoader This plugin enables FreeCAD to import Inventor part files (*.IPT), ACIS files (*.SAT, *.SAB), 3D-Solids from DXF files and Fusion360 (*.f3d) files. ['jmplonka'] 1.5.1 master 95.6 1 1 4 2 yr 5,390 827 169 59 24 39 master LGPL-3.0-or-later 2017-02-09
110 Road Road is the Transportation and Geomatics Engineering workbench for FreeCAD. ['Hakan Seven'] 2026.04.11 main 95.6 0 3 14 3 mo 3,118 25 50 9 11 128 main LGPL-2.1-or-later, CC-BY-SA-4.0 2025-01-01
111 MeshToFeatures Reverse-engineer triangle meshes (STL) of prismatic parts into editable PartDesign bodies: surface recognition, design-intent parameter snapping, feature detection, and build-history reconstruction. ['Masoud Masoumi'] 0.17.6 main 95.5 1 1 5 6 d 716 551 15 0 2 63 main v0.17.6 LGPL-2.1-or-later 2026-07-11
112 btl A FreeCAD Path Addon to manage your tool library. ['Samuel Abels'] 0.9.9 main 95.5 1 1 5 1 yr 292 0 43 17 16 49 main MIT 2023-07-15
113 Nesting A workbench for 2D nesting of shapes, using no-fit-polygon (Minkowski sum) placement with a genetic algorithm optimizer. Includes a manual nester, sheet stacking, DXF export and CAM job creation. ['Steve Peters'] 2026.9.0 main 95.3 0 3 17 8 d 324 324 10 7 3 60 main LGPL-2.1-or-later, OFL-1.1 2025-10-24
114 GearWorkBench Designs parametric gears for 3D printing — spur, helical, rack, bevel, and cycloidal, with circular, square, hexagonal, and DIN keyway bores. ['Chris Bruner'] 1.4 1.4 94.9 1 0 21 2 d 147 147 5 0 2 37 1.4 1.4 LGPL-2.1-or-later 2025-12-11
115 DynamicData Container object for holding custom properties, alternative to spreadsheet ['TheMarkster'] 2.78 master 94.9 1 2 1 6 mo 2,858 0 51 24 10 4 master LGPL-2.1-or-later 2018-09-22
116 MeshStudy Automates mesh refinement studies for (FEA/FEM). ['Abdalla Abbas'] 0.1.3 main 94.8 1 2 2 13 d 0 0 4 0 1 28 main v0.1.3 LGPL-2.1-or-later 2026-08-19
117 3D_Printing_Tools [] master 94.6 1 2 4 7 yr 7,351 924 55 7 22 5 master 2019-01-30
118 Assembly3 Assembly3 workbench an attempt to bring assembly capability to FreeCAD using SolveSpace constraint solver ['RealThunder'] 0.12.3 master 94.6 1 2 4 11 mo 4,702 558 906 334 74 18 master GPL-3.0-only 2017-09-10
119 DesignSPHysics DesignSPHysics is a macro/addon for FreeCAD that provides a Graphical User Interface for fluid and multi-physics solver DualSPHysics ['Iván Martínez Estévez'] 0.8.2 (29-05-2026) master 94.4 0 4 16 4 mo 1,715 212 155 32 46 315 master GPL-3.0-or-later 2018-07-31
120 SimplyPrint Send your FreeCAD models, meshes and assemblies directly to the SimplyPrint cloud for slicing, storage and 3D printing. Adapts to the active workbench, lets you choose the mesh quality when exporting parametric solids, and shows the real size of what you're about to send. ['SimplyPrint'] 1.0.0 main 94.4 0 5 6 3 mo 0 0 0 0 1 17 main MIT 2026-06-01
121 FreeCAD-themes Additional themes for FreeCAD ['The FreeCAD Team'] 2026.08.16 main 94 2 0 0 2 mo 15,875 2,501 13 2 3 0 main LGPL-2.1-or-later 2024-06-24
122 NordicFC Nordic themes and preference pack. ['error on line 1'] 1.0.1 main 94 2 0 0 5 mo 2,908 515 24 2 2 0 main LGPL-2.1-or-later 2025-09-20
123 OpticsWorkbench Geometrical optics for FreeCAD. Performs simple raytracing through your FreeCAD objects. ['Christi'] 1.3.9 main 94 2 0 0 2 mo 4,196 459 172 14 38 16 main LGPL-2.1 2021-07-03
124 Estimate A FreeCAD workbench to estimate material quantity by volume or weight for selected parts ['error on line 1'] 0.1.5 master 94 2 0 0 5 mo 2,312 0 15 1 5 6 master LGPL-3.0-or-later 2022-03-04
125 SlopedPlanesMacro [] master 94 2 0 0 8 yr 0 0 4 0 4 14 master 2017-11-14
126 CfdOF Computational Fluid Dynamics (CFD) based on OpenFOAM. ['Oliver Oxtoby'] 1.37.3 master 93.9 0 4 21 4 mo 23,784 2,645 722 26 136 74 master v1.37.3 LGPL-3.0-or-later 2016-12-02
127 PieMenu The PieMenu module is a tool to accelerate and simplify your workflow in usage of FreeCAD. ['Grubuntu'] 1.13 master 93.9 2 0 1 4 mo 11,628 2,312 40 0 9 7 master LGPL-2.1-or-later 2024-01-13
128 Freecad-Built-in-themes-beta Beta versions of the preference Packs included with the FreeCAD distribution ['MisterMaker'] 1.2.2 main 93.9 2 0 1 2 yr 2,587 177 4 1 4 0 main LGPL-2.0-or-later 2023-06-11
129 Machines Collection of Community Maintained Machines ['Sliptonic'] 1.0.0 Latest 93.9 2 0 1 1 mo 0 0 6 4 6 0 Latest CC-BY-SA-4.0 2026-03-13
130 STEMFIE A simple workbench for generating STEMFIE system components. ['Bilbao Makers', 'hasecilu'] 0.3.1 main 93.9 2 0 1 2 yr 0 0 25 5 4 15 main 0.3.1 GPL-2.0-or-later 2021-07-06
131 SteelColumn [] master 93.9 2 0 1 2 yr 0 0 9 0 4 16 master 2020-08-28
132 OpenTheme An accessible and coordinated set of Light and Dark themes for FreeCAD ['Obelisk79'] 2026.10.03 main 93.8 2 0 2 today 56,918 6,283 117 50 16 2 main LGPL-2.1-or-later 2024-01-24
133 Color-Palette-Theme Choose your colors with the "ColorPalette" Theme and increase the focus on objects and texts(FreeCAD v1.1.0 ≥) ['altangarts'] 2.4.4 main 93.8 2 0 2 today 7,820 1,243 14 1 2 7 main LGPL-2.1-or-later 2024-12-25
134 Alternate_OpenSCAD An alternate OpenSCAD importer with some experimental features. ['Keith Sloan'] 1.0.0 master 93.7 0 4 23 2 mo 4,903 693 17 10 8 19 master LGPL-2.1-or-later 2020-02-04
135 FreeCAD-Ribbon A customizable ribbon interface for FreeCAD ['Paul Ebbers'] 1.12.0dev Develop 93.6 1 0 34 4 d 0 0 140 7 14 48 Develop GPL-3.0-or-later 2024-09-28
136 nurbs [] master 93.4 1 2 16 7 yr 0 0 26 6 12 110 master 2016-08-01
137 Lapidary Design faceted gemstones: parametric facet tiers driven by index gear, angle and index list. GemCad .ASC interchange, printable 2D faceting diagrams, cutting sheets, and ray-traced optics studies. ['Dominic'] 0.2.0 main 93.2 1 3 8 20 d 0 0 1 0 1 82 main LGPL-2.1-or-later 2026-08-22
138 Design456 Direct Modeling Workbench for FreeCAD ['Mariwan Jalal'] 0.00.1 main 93.1 2 0 9 2 d 2,156 47 65 4 6 80 main GPL-3.0-or-later 2021-01-29
139 workfeature [] master 93 2 1 0 2 yr 0 0 13 6 5 35 master 2018-01-29
140 Assembly4.1 This assembly workbench use lets you put FreeCAD Part and Body together inside a standard Assembly container. ['leoheck'] 0.61.0-0.2 main 92 1 5 0 4 mo 11,883 1,369 23 4 7 33 main LGPL-2.1-only 2025-06-23
141 SaveAndRestore A simple addon to save and restore your settings ['Paul Ebbers'] 1.1 main 91.6 1 3 24 5 d 10,035 1,210 11 1 1 11 main MIT 2025-04-23
142 FreeCAD-Ribbon A customizable ribbon interface for FreeCAD ['Paul Ebbers'] 1.11.10 main 91.5 0 5 35 5 d 10,598 1,887 140 7 14 49 main GPL-3.0-or-later 2024-09-28
143 OSAFE This is a workbench for FreeCAD that creates foundation model from CSI ETABS model results. ['Raeyat Roknabadi Ebrahim'] 2022.05.29 master 91.3 0 7 17 8 mo 0 0 56 3 12 83 master LGPL-2.1-or-later 2018-11-08
144 Assembly4 This assembly workbench allows you to assemble various native FreeCAD parts (of type Part or Body) into a standard assembly container through links, and place them relative to the assembly and to each other using LCS connectors. ['Zolko'] 0.61.1 main 91 1 5 10 3 mo 23,272 2,478 0 0 0 40 main LGPL-2.1-only
145 Gridfinity This Workbench will generate several variations of parametric Gridfinity bins and baseplates that can be easily customized. ['Stuart'] 0.12.4 master 91 3 0 0 7 mo 14,803 1,467 533 41 56 17 master v0.12.4 lgpl-2.1-or-later 2024-03-18
146 QuickMeasure Measures selected features. [] 2022.10.28 main 91 3 0 0 1 yr 5,773 569 11 4 7 3 main 2022-10-04
147 MyCustomPiping A parametric piping workbench for FreeCAD. Generates pipes, flanges, fittings, valves, and gaskets sized directly from CSV databases based on ASME, MSS, and API standards. Every component is fully parametric — change size, class, or schedule after creation and the geometry rebuilds automatically. ['RamDj12049'] 1.1.0 main 91 3 0 0 2 mo 797 382 2 0 0 48 main LGPL-2.1-or-later 2026-07-27
148 BulletDesigner Parametric bullet design workbench with ballistic and trajectory tools. ['Bullet Designer Team'] 1.0.0 main 91 3 0 0 5 mo 0 0 5 0 1 19 main MIT 2026-02-20
149 Launcher Search for commands and run them. ['PhoneDroid', 'Triplus'] 0.1.0 Latest 91 3 0 0 6 mo 0 0 1 0 4 7 Latest LGPL-2.1-or-later, CC-BY-SA-4.0 2026-03-28
150 Machines Collection of Community Maintained Machines ['Sliptonic'] 1.0.0 Stable 90.9 3 0 1 6 mo 0 0 6 4 6 0 Stable v1.0.0 CC-BY-SA-4.0 2026-03-13
151 CADExchanger [] master 90.7 3 0 3 2 yr 2,536 290 78 6 11 3 master 2017-03-25
152 pyrate [] master 90.4 2 3 6 2 yr 0 0 0 0 0 123 master
153 Render (UNMAINTAINED) A workbench to produce high-quality rendered images from your FreeCAD document, using open-source external rendering engines. Designed as a modern replacement for deprecated internal Raytracing Workbench. ['Yorik Van Havre', 'No current maintainer', 'howetuft'] 2024.12.15 master 90.3 1 5 17 5 mo 15,339 1,897 237 21 44 53 master LGPL-2.1-or-later 2017-12-17
154 woodworking Woodworking workbench was designed primarily for creating simple cabinets for your home or garage. However, it includes many features that will make everyday carpentry and other CAD projects easier and faster. I hope you will find something you enjoy here. ['Darek L'] 3.3.20260801 master 90.2 0 8 18 2 mo 29,866 2,748 570 0 51 159 master MIT 2022-02-25
155 EasyProfileFrame Simplifies the creation of frames using profiles, such as aluminum profiles. It also includes support for exporting Bill of Materials (BOM). ['ovo-Tim'] 0.0.1 main 89.9 3 1 1 1 yr 5,293 645 29 7 4 10 main LGPL-3.0-or-later 2025-01-19
156 Smooth-Toolsync Synchronize FreeCAD's CAM tool libraries with a Loobric tool data server. Adds "Loobric" to the CAM workbench toolbar (a modeless Sync / Machines / Audit log window) and a preference page for server configuration. Current capabilities (v2): - Two-way sync of tool bits and tool libraries: a plan/apply preview shows what changed on each side; upload local edits or download server changes, losslessly and without ever duplicating - Synced files carry their server identity; unknown keys (e.g. F&S presets) survive round trips untouched - Machines view: browse each machine's tool table and confirm which physical tool is bound to each entry Requirements: - FreeCAD 1.1 or later with the CAM workbench - A Loobric server (self-hosted or hosted) - see https://loobric.com - Standard library only: no extra Python packages ['Brad Collette'] 0.7.0 master 89.9 3 1 1 2 mo 0 0 5 1 0 37 master MIT 2025-10-27
157 MBDWorkbench Model-Based Definition workbench for semantic PMI authoring, validation, AP242 STEP export, and first-pass AP242 semantic PMI import. ['Chip'] 0.1.0 main 89.7 0 9 13 2 mo 0 0 0 1 0 32 main LGPL-2.1-only 2026-05-16
158 osh-autodoc-workbench A workbench that support the creation of assembly manuals of open source hardware. ['J.C. Mariscal-Melgar', 'Pieter Hijma'] 0.2.3 main 89 1 8 0 8 mo 0 0 0 0 0 23 main LGPL-3.0-or-later
159 SaveAndRestore A simple addon to save and restore your settings ['Paul Ebbers'] 1.1.1 Develop 88.6 2 3 24 4 d 0 0 11 1 1 11 Develop MIT 2025-04-23
160 KiConnect PCB Syncronization with KiCAD v9+ ['morgan'] 1.0.1 release 88.4 0 11 6 2 mo 196 30 0 0 0 30 release v1.0.1 LGPL-2.1-or-later
161 TitleBlock An extension for the TechDraw workbench to fill a TitleBlock with the aid of the Spreadsheet workbench. ['Paul Ebbers'] 0.5.2.2 main 88.3 3 2 7 1 yr 0 0 5 2 0 18 main LGPL-2.1-or-later 2023-10-07
162 Launcher Search for commands and run them. ['PhoneDroid', 'Triplus'] 0.1.0 Stable 88 4 0 0 6 mo 0 0 1 0 4 2 Stable v0.1.0 LGPL-2.1-or-later, CC-BY-SA-4.0 2026-03-28
163 SearchBar Adds a search bar widget for tools, document objects, and preferences ['Paul Ebbers'] 1.8.0 Develop 87.6 3 3 4 12 mo 0 0 6 9 9 28 Develop CCOv1 2024-11-07
164 kicadStepUpMod A bidirectional ECAD/MCAD collaboration between KiCAD and FreeCAD. ['Maui'] 11.09.6 master 85.9 3 4 11 29 d 20,740 3,194 690 42 84 34 master AGPLv3.0 2017-09-12
165 fcVM Finite element collapse analysis based on the von Mises plasticity model for use with FreeCAD ['HarryvL'] 2024.9.5 main 85.9 4 2 1 1 yr 0 0 11 3 3 4 main 2024-01-17
166 FreeGrid A simple tools workbench for generating FreeGrid storage system components. ['Michael K Johnson', 'Alan Langford', 'hasecilu'] 2.2.0 main 85.4 4 2 6 2 yr 1,209 0 51 2 4 9 main AGPL-3.0-or-later 2022-07-25
167 freecad_streamdeck_addon FreeCAD addon to use an Elgato Stream Deck macropad as an input device. ['Giraut'] 0.1.7 main 85 5 0 0 3 yr 0 0 21 8 8 6 main GPL-3.0-or-later 2024-02-25
168 FEMbyGEN Parametric Finite Element Analysis(FEM) ['Serdar T. Ince'] 2.5.5 master 84.9 2 9 1 5 mo 3,396 360 51 7 25 28 master LGPL-2.1-only 2022-07-27
169 drawing_dimensioning [] < 0.20 84.5 3 6 5 11 mo 0 0 1 0 48 59 v0.19.4 0.19.4 2025-11-03
170 Manipulator A handy way to Move and Align objects in FreeCAD. ['Maui'] 1.6.4 master 83.6 3 7 4 6 mo 14,250 1,533 76 24 14 10 master GPLv3.0 2017-10-02
171 Part-o-magic Experiment on FreeCAD-wide automation of Part container management ['DeepSOIC'] 1.1.0 master 83.5 0 16 5 5 mo 44 0 15 28 5 62 master LGPL-2.0-or-later 2016-05-20
172 A2plus Another assembly workbench for FreeCAD, following and extending Hamish's Assembly 2 workbench hence Assembly2plus. The main goal of A2plus is to create a very simple, easy to use, and not over-featured workbench for FreeCAD assemblies. Using the KISS principle: KEEP IT SIMPLE, STUPID ['kbwbe'] 0.4.68 master 83 4 1 40 8 mo 27,910 3,520 206 49 72 38 master LGPL-2.1-or-later 2018-06-28
173 FEM_FrontISTR A FreeCAD addon that enables a parallel nonliner FEM solver FrontISTR. ['FrontISTR-Commons'] 0.2.0 master 82.9 5 1 11 1 yr 446 0 37 0 9 29 master LGPL-2.1-or-later 2021-04-03
174 Reinforcement A workbench that provides tools for Reinforcement Generation and its Detailing. ['Amritpal Singh (amrit3701)'] v0.6 master 82.7 1 12 23 7 mo 2,708 326 66 60 22 66 master LGPL-2.1-or-later 2017-04-09
175 Rocket A workbench for designing model rockets. ['David Carter'] 3.3.0 Pre-1.0 Compatible 81.5 4 6 5 3 yr 0 0 79 10 19 266 v3.3.0 v3.3.0 LGPLv2.1 2021-02-01
176 freecad.optics_design_workbench Physically accurate forward ray tracing for optics simulation and optimization with FreeCAD workbench frontend. ['Philipp Bredol'] 1.2.8 master 78.8 4 4 52 16 d 2,078 345 16 0 4 73 master LGPL-3.0-or-later 2024-07-17
177 Cfd [] master 77.3 5 4 37 5 yr 26 0 214 4 43 66 master 2016-09-29
178 Corridor-Road FreeCAD workbench for parametric road corridor design, review, and output preparation. ['Kcod'] 1.1.0 Latest 77.2 1 2 178 14 d 130 0 11 1 3 660 main LGPL-2.1-or-later 2026-02-23
179 WebTools A collection of tools to work with web services ['Yorik van Havre'] 1.0.0 master 76.3 1 20 7 1 yr 0 0 29 11 18 10 master LGPL-2.1-or-later 2017-04-08
180 GDML An external workbench for creating GDML models for Geant4 and Root ['Keith Sloan'] 2.2.8 Main 74.9 0 22 31 1 mo 832 0 72 50 23 78 Main LGPL-2.1 2019-11-21
181 boltsfc Installable FreeCAD package of BOLTS, an Open Library for Technical Specifications. ['Bernd Hahnebach'] 2022.11.5 main 69.8 3 21 2 4 yr 8,409 1,088 41 3 15 51 main LGPLv2.1 2017-07-02
182 Ondsel-Lens Workspace manager for Ondsel Lens workspaces ['Pieter Hijma'] 2025.12.22.01 main 68.4 6 13 6 10 mo 0 0 11 15 13 66 main LGPL-2.0-or-later, Apache-2.0, CC0-1.0, CC-BY-SA-2.0, CC-BY-SA-4... 2025-06-22
183 Rocket Workbench for designing model rockets. ['David Carter'] 5.1.3 master 67.8 5 14 32 2 mo 1,892 392 79 10 19 312 master v5.1.3 LGPL-2.1-or-later, MIT 2021-02-01
184 EMStudio RF and electromagnetic modeling and simulation inside FreeCAD. EMStudio provides a guided workflow (geometry - materials - ports/boundaries - mesh - solve - results) that drives open-source solvers (openEMS FDTD, NEC2 MoM, FastHenry PEEC, Elmer FEM, AWS Palace FEM, OpenFOAM CFD) as isolated backends. A free alternative to CENOS RF and Ansys HFSS-class tools. ['ajj3.us'] 1.13.0 master 63.8 0 28 82 today 1,226 588 7 0 0 285 master LGPL-2.1-or-later 2026-07-27
185 AnimationFreeCAD The FreeCAD Animation workbench allows users to animate any object easily through visual scripting Nodes thanks to PyFlow. ['Andréas Cottet', 'Quentin Tournier'] 1.0-beta main 44.1 2 44 59 2 yr 3,081 403 33 10 10 630 main Apache-2.0 2022-01-29
186 workfeature-macro [] master 17.9 1 79 1 2 yr 0 0 28 3 9 34 master 2015-02-15
187 AIGenFurniture Parametric furniture cabinet design workbench. Generate cabinets from simple boxes, apply features (fronts, shelves, drawers), and export manufacturing files. ['Bogdan'] 0.2.0 Latest 0 7 159 199 5 d 4,401 912 12 0 4 875 main v0.2.0 LGPL-2.1-or-later 2025-08-27
188 pcb Printed Circuit Board (PCB) Workbench for FreeCAD ['marmni'] 6.2023.1 master 0 3 101 43 7 mo 5,662 623 121 7 30 280 master AGPLv3.0 2016-01-06

Addon Details

fasteners master

0.5.67· Some common fasteners and fastener tools for FreeCAD.

100 / 100

Repository

https://github.com/shaise/FreeCAD_FastenersWB
master · V0.5.67-beta · Created: 2015-06-18 · Updated: 23 d · 94 python files

Statistics

192,678
DL(Yr)
29,578
DL(Mo)
420
Stars
85
Issues
Manifest
Branch
master
Version
0.5.67
License
GPL-2.0-or-later
Dependencies 5
  • Compat: PySide2
  • Internal: Draft
  • Internal: PySide
  • Warn: pytest (Not in AddonManager allowed packages)
  • Warn: utils (Not in AddonManager allowed packages)
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Shai Seger

ThreadProfile master

2.03· ThreadProfile object for creating internal/external threads

100 / 100

Repository

https://github.com/mwganson/ThreadProfile
master · Created: 2019-07-22 · Updated: 19 d · 6 python files

Statistics

19,318
DL(Yr)
3,370
DL(Mo)
80
Stars
30
Issues
Manifest
Branch
master
Version
2.03
License
LGPL-2.1
Dependencies 2
  • Internal: Draft
  • Internal: PySide
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
TheMarkster

CurvedShapes master

1.00.15· Create 3D shapes from 2D curves.

100 / 100

Repository

https://github.com/chbergmann/CurvedShapesWorkbench
master · Created: 2019-06-11 · Updated: 4 mo · 12 python files

Statistics

23,871
DL(Yr)
2,814
DL(Mo)
87
Stars
12
Issues
Manifest
Branch
master
Version
1.00.15
License
LGPL-2.1
Dependencies 4
  • Internal: BOPTools
  • Internal: Draft
  • Internal: PySide
  • Internal: Sketcher
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Christi

FusedFilamentDesign release

0.26.360· PartDesign addon for FFF/FDM 3D-printing design

100 / 100

Repository

https://github.com/rahix/FusedFilamentDesign.git
release · v0.26.360 · Created: 2025-05-11 · Updated: 1 mo · 11 python files

Statistics

15,785
DL(Yr)
2,343
DL(Mo)
251
Stars
17
Issues
Manifest
Branch
release
Version
0.26.360
License
LGPL-2.1-or-later
Dependencies 3
  • Internal: BOPTools
  • Internal: PySide
  • Internal: Sketcher
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
rahix

AddonManager main

2026.9.26· Tool to install workbenches, macros, themes, etc.

100 / 100

Repository

https://github.com/FreeCAD/AddonManager
main · Created: 2025-04-06 · Updated: 7 d · 111 python files

Statistics

22,260
DL(Yr)
2,280
DL(Mo)
19
Stars
28
Issues
Manifest
Branch
main
Version
2026.9.26
License
LGPL-2.1-or-later
Dependencies 11
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Pip: Markdown
  • Pip: Requests
  • Pip: defusedxml
  • Pip: importlib_metadata
  • Pip: pyfakefs
  • Pip: scour
  • Warn: freecad_addon_analyzer (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer.egg (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 4
Jonathan Wiedemann Kurt Kremitzki Yorik van Havre Chris Hennes

ThreadWorkbench master

0.3.1· Thread Workbench is a FreeCAD workbench for generating metric and inch threads

100 / 100

Repository

https://github.com/krwork3d/freecad_thread_workbench
master · version_change · Created: 2026-05-30 · Updated: 3 mo · 45 python files

Statistics

7,607
DL(Yr)
2,159
DL(Mo)
11
Stars
3
Issues
Manifest
Branch
master
Version
0.3.1
License
GPL-3.0-or-later
Dependencies 2
  • Internal: PySide
  • Internal: pivy
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
ThreadWorkbench

SearchBar main

1.8.2· Adds a search bar widget for tools, document objects, and preferences

100 / 100

Repository

https://github.com/APEbbers/SearchBar
main · Created: 2024-11-07 · Updated: 2 d · 27 python files

Statistics

9,040
DL(Yr)
1,645
DL(Mo)
6
Stars
9
Issues
Manifest
Branch
main
Version
1.8.2
License
CCOv1
Dependencies 4
  • Internal: PySide
  • Internal: pivy
  • Pip: defusedxml
  • Pip: lxml
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

Silk master

0.4.0· NURBS Surface modeling tools focused on low degree and seam continuity

100 / 100

Repository

https://github.com/edwardvmills/Silk
master · Created: 2017-05-20 · Updated: 2 mo · 43 python files

Statistics

11,647
DL(Yr)
1,073
DL(Mo)
96
Stars
5
Issues
Manifest
Branch
master
Version
0.4.0
License
GPL-3.0-or-later
Dependencies 2
  • Internal: PySide
  • Pip: numpy
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
edwardvmills

dodo master

1.0.1· A set of commands and objects that help to speed-up the drawing of frames and pipelines. Py3/Qt5 port of flamingo.

100 / 100

Repository

https://github.com/oddtopus/dodo
master · Created: 2019-03-24 · Updated: 2 yr · 18 python files

Statistics

4,839
DL(Yr)
733
DL(Mo)
31
Stars
20
Issues
Manifest
Branch
master
Version
1.0.1
License
LGPLv3
Dependencies 6
  • Internal: Arch
  • Internal: BOPTools
  • Internal: Draft
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Riccardo Treu (oddtopus)

Behave-Dark-Colors main

0.1.1· A preference pack including GUI color information to extend the Behave Dark stylesheet

100 / 100

Repository

https://github.com/Chrismettal/FreeCAD-Behave-Dark-Preference-Pack
main · Created: 2022-01-30 · Updated: 2 yr · 0 python files

Statistics

4,738
DL(Yr)
553
DL(Mo)
11
Stars
2
Issues
Manifest
Branch
main
Version
0.1.1
License
GPL-3.0-only
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Chrismettal

Woods master

1.1.0· Collection of various wood materials.

100 / 100

Repository

https://github.com/davesrocketshop/Woods
master · v1.1.0 · Created: 2025-06-26 · Updated: 9 mo · 4 python files

Statistics

5,274
DL(Yr)
543
DL(Mo)
13
Stars
3
Issues
Manifest
Branch
master
Version
1.1.0
License
LGPL-2.1-or-later, CDLA-Sharing-1.0, CC-BY-SA-4.0
Dependencies 3
  • Pip: Pillow
  • Pip: openpyxl
  • Warn: opencv-python (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
David Carter Gregory Holmberg

Marz master

0.1.22· Parametric Guitar design workbench

100 / 100

Repository

https://github.com/mnesarco/MarzWorkbench
master · v0.1.22 · Created: 2020-04-05 · Updated: 2 mo · 67 python files

Statistics

4,504
DL(Yr)
528
DL(Mo)
134
Stars
7
Issues
Manifest
Branch
master
Version
0.1.22
License
GPL-3.0-or-later, LGPL-2.1-or-later
Dependencies 11
  • Compat: PySide2
  • Compat: PySide6
  • Internal: BOPTools
  • Internal: PySide
  • Internal: TechDraw
  • Internal: pivy
  • Pip: defusedxml
  • Pip: numpy
  • Warn: gi (Not in AddonManager allowed packages)
  • Warn: inkex (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Frank Martinez

Dracula master

0.0.9· Dracula dark theme for FreeCAD

100 / 100

Repository

https://github.com/dracula/freecad
master · Created: 2021-03-07 · Updated: 1 yr · 0 python files

Statistics

4,572
DL(Yr)
505
DL(Mo)
38
Stars
9
Issues
Manifest
Branch
master
Version
0.0.9
License
MIT
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Eleanor Clifford

Catppuccin main

1.0.0· Light / Dark theme and preference pack.

100 / 100

Repository

https://github.com/cnvuls/CatppuccinTheme
main · Created: 2026-04-04 · Updated: 5 mo · 0 python files

Statistics

2,271
DL(Yr)
383
DL(Mo)
5
Stars
1
Issues
Manifest
Branch
main
Version
1.0.0
License
MIT
Static Analysis 0
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
cnvuls

FileExplorerExt main

1.0.7· Integrated file system viewer.

100 / 100

Repository

https://github.com/mnesarco/FileExplorerExt
main · v1.0.7 · Created: 2025-12-24 · Updated: 29 d · 22 python files

Statistics

1,555
DL(Yr)
381
DL(Mo)
5
Stars
0
Issues
Manifest
Branch
main
Version
1.0.7
License
LGPL-3.0-or-later
Dependencies 3
  • Compat: PySide6
  • Internal: PySide
  • Pip: scour
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Frank David Martínez Muñoz

Supplemental-Materials Latest

1.0.2· Materials database that supplements the core materials.

100 / 100

Repository

https://github.com/FreeCAD/Supplemental-Materials
Latest · Created: 2026-03-01 · Updated: 1 mo · 2 python files

Statistics

1,037
DL(Yr)
368
DL(Mo)
8
Stars
0
Issues
Manifest
Branch
Latest
Version
1.0.2
License
LGPL-3.0-or-later, CC-BY-SA-4.0
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
DavesRocketShop

StandardBeams main

1.0.0· Workbench to create standard beam profiles of varying shapes.

100 / 100

Repository

https://github.com/MortenVajhoj/StandardBeams
main · Created: 2026-01-14 · Updated: 8 mo · 56 python files

Statistics

3,062
DL(Yr)
352
DL(Mo)
6
Stars
0
Issues
Manifest
Branch
main
Version
1.0.0
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Dependencies 2
  • Compat: PySide6
  • Internal: PySide
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Morten Vajhøj

SvgWorkbench main

1.0.0.dev15· FreeCAD Svg Workbench

100 / 100

Repository

https://github.com/mnesarco/SvgWorkbench
main · Created: 2025-02-07 · Updated: 2 mo · 71 python files

Statistics

2,671
DL(Yr)
328
DL(Mo)
12
Stars
1
Issues
Manifest
Branch
main
Version
1.0.0.dev15
License
LGPL-3.0-or-later, LGPL-2.1-or-later
Dependencies 12
  • Compat: PySide6
  • Compat: shiboken2
  • Compat: shiboken6
  • Internal: Draft
  • Internal: PySide
  • Internal: TechDraw
  • Internal: pivy
  • Pip: defusedxml
  • Pip: packaging
  • Pip: rich
  • Warn: toml (Not in AddonManager allowed packages)
  • Warn: typer (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Frank David Martínez Muñoz

Beltrami main

1.3.3· Workbench for designing Turbomachine blades.

100 / 100

Repository

https://github.com/Simturb/Beltrami
main · 1.3.3 · Created: 2021-05-10 · Updated: 5 mo · 5 python files

Statistics

3,789
DL(Yr)
285
DL(Mo)
43
Stars
0
Issues
Manifest
Branch
main
Version
1.3.3
License
LGPL-2.1-or-later
Dependencies 4
  • Internal: Sketcher
  • Internal: Spreadsheet
  • Pip: numpy
  • Pip: scipy
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Michel Sabourin

FeedsAndSpeeds master

0.6· CAM addon to help generate basic feeds and speeds for machining.

100 / 100

Repository

https://github.com/dubstar-04/FeedsAndSpeeds
master · Created: 2020-04-10 · Updated: 10 mo · 4 python files

Statistics

2,622
DL(Yr)
202
DL(Mo)
50
Stars
17
Issues
Manifest
Branch
master
Version
0.6
License
LGPL-2.1-or-later
Dependencies 2
  • Internal: PySide
  • Pip: Path
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Daniel Wood

BananaForScale main

1.1.0· Adds a banana for scale to FreeCAD.

100 / 100

Repository

https://github.com/FabioTavernini/bananaforscale
main · Created: 2026-07-04 · Updated: 2 mo · 3 python files

Statistics

872
DL(Yr)
169
DL(Mo)
8
Stars
0
Issues
Manifest
Branch
main
Version
1.1.0
License
MIT, CC-BY-4.0, CC0-1.0
Dependencies 1
  • Internal: Mesh
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Fabio Tavernini

Movie master

2026.08.23· Workbench to create and animate the movie camera, create and play videos of animations

100 / 100

Repository

https://github.com/Francisco-Rosa/FreeCAD-Movie
master · Created: 2022-12-12 · Updated: 1 mo · 6 python files

Statistics

597
DL(Yr)
162
DL(Mo)
15
Stars
0
Issues
Manifest
Branch
master
Version
2026.08.23
License
LGPL-2.1-or-later
Dependencies 4
  • Internal: PySide
  • Internal: pivy
  • Mod: Render
  • Warn: opencv-python (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
F_Rosa

Telemetry main

1.0.7· Help improve FreeCAD by sending basic metrics to the development team.

100 / 100

Repository

https://github.com/FreeCAD/FreeCAD-Telemetry
main · Created: 2025-02-16 · Updated: 21 d · 9 python files

Statistics

1,992
DL(Yr)
125
DL(Mo)
13
Stars
6
Issues
Manifest
Branch
main
Version
1.0.7
License
LGPL-2.1-or-later, CC-BY-4.0
Dependencies 3
  • Internal: PySide
  • Pip: posthog
  • Warn: sentry_sdk (Not in AddonManager allowed packages)
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
The FreeCAD project association AISBL

BrickFace main

0.2.1· Transform a planar face into a LEGO-compatible face (studs or sockets) from the Part Design Face Tools task panel.

100 / 100

Repository

https://github.com/jacquesh82/FreeCAD-BrickFace
main · Created: 2026-08-23 · Updated: 1 mo · 7 python files

Statistics

17
DL(Yr)
17
DL(Mo)
3
Stars
0
Issues
Manifest
Branch
main
Version
0.2.1
License
MIT
Dependencies 1
  • Internal: PySide
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Jacques Hullu

AddonManager dev

2026.9.26dev· Development branch of a tool to install workbenches, macros, themes, etc.

100 / 100

Repository

https://github.com/FreeCAD/AddonManager
dev · Created: 2025-04-06 · Updated: 7 d · 111 python files

Statistics

0
DL(Yr)
0
DL(Mo)
19
Stars
28
Issues
Manifest
Branch
dev
Version
2026.9.26dev
License
LGPL-2.1-or-later
Dependencies 11
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Pip: Markdown
  • Pip: Requests
  • Pip: defusedxml
  • Pip: importlib_metadata
  • Pip: pyfakefs
  • Pip: scour
  • Warn: freecad_addon_analyzer (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer.egg (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 4
Jonathan Wiedemann Kurt Kremitzki Yorik van Havre Chris Hennes

Channels main

0.1.0.dev4· FreeCAD Channels - Connector to Blender

100 / 100

Repository

https://github.com/mnesarco/Channels
main · Created: 2025-04-11 · Updated: 6 mo · 41 python files

Statistics

89
DL(Yr)
0
DL(Mo)
75
Stars
0
Issues
Manifest
Branch
main
Version
0.1.0.dev4
License
LGPL-3.0-or-later
Dependencies 13
  • Compat: PySide2
  • Compat: PySide6
  • Compat: shiboken2
  • Compat: shiboken6
  • Internal: PySide
  • Internal: pivy
  • Pip: defusedxml
  • Pip: packaging
  • Pip: rich
  • Warn: bpy (Not in AddonManager allowed packages)
  • Warn: importers (Not in AddonManager allowed packages)
  • Warn: toml (Not in AddonManager allowed packages)
  • Warn: typer (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Frank David Martínez Muñoz

FoamCut main

0.2.0· Foamcut workbench provide functionality to prepare job and generate Gcode for 4 or 5 axis cnc hotwire cutter.

100 / 100

Repository

https://github.com/Shkolik/Foamcut
main · Created: 2024-01-12 · Updated: 2 mo · 25 python files

Statistics

613
DL(Yr)
0
DL(Mo)
24
Stars
4
Issues
Manifest
Branch
main
Version
0.2.0
License
LGPL-2.1-or-later
Dependencies 2
  • Internal: PySide
  • Internal: pivy
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 2
Andrew Shkolik (https://github.com/Shkolik) Andrew Shkolik

FreecadDiscordPresence main

1.0.3· Shows FreeCAD Status on discord.

100 / 100

Repository

https://github.com/TzurSoffer/FreecadDiscordPresence
main · Version1.0.3 · Created: 2024-12-09 · Updated: 1 yr · 4 python files

Statistics

0
DL(Yr)
0
DL(Mo)
20
Stars
0
Issues
Manifest
Branch
main
Version
1.0.3
License
LGPL-2.1-or-later
Dependencies 3
  • Compat: PySide2
  • Internal: PySide
  • Pip: pypresence
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Tzur Soffer

ImportNURBS master

1.1 Beta· An external workbench for add importer for 3dm>

100 / 100

Repository

https://github.com/KeithSloan/ImportNURBS
master · Created: 2020-03-23 · Updated: 6 mo · 4 python files

Statistics

0
DL(Yr)
0
DL(Mo)
13
Stars
4
Issues
Manifest
Branch
master
Version
1.1 Beta
License
LGPL-2.1
Dependencies 4
  • Internal: Draft
  • Internal: Mesh
  • Pip: rhino3dm
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Keith Sloan

InstrumentInput main

0.3.1· Use Bluetooth-connected measurement instruments such as calipers as input devices

100 / 100

Repository

https://codeberg.org/stv0g/freecad-instrumentinput
main · Updated: 4 mo · 9 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
main
Version
0.3.1
License
Apache-2.0
Dependencies 2
  • Compat: PySide6
  • Warn: sylvac (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Steffen Vogel (stv0g)

Pyramids-and-Polyhedrons Latest

0.2.2· Create various polyhedrons in the Part workbench.

100 / 100

Repository

https://github.com/Addon-Shelter/Polyhedra
Latest · Created: 2025-09-14 · Updated: 6 mo · 32 python files

Statistics

878
DL(Yr)
0
DL(Mo)
1
Stars
0
Issues
Manifest
Branch
Latest
Version
0.2.2
License
GPL-3.0-or-later, CC-BY-SA-4.0, Unlicense
Dependencies 1
  • Compat: PySide6
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
Eddy Verlinden PhoneDroid

Templater main

0.0.6· A workbench to gather some drafting related tools

100 / 100

Repository

https://codeberg.org/FBXL5/Templater
main · Updated: 4 mo · 10 python files

Statistics

264
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
main
Version
0.0.6
License
LGPL-3.0-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
FBXL5

TexturedObjImporter main

0.1.1· Import UV-mapped OBJ meshes with MTL and image textures.

100 / 100

Repository

https://github.com/mlaffran/TexturedObjImporter
main · Created: 2026-08-21 · Updated: 1 mo · 8 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
main
Version
0.1.1
License
LGPL-2.1-or-later
Dependencies 2
  • Internal: PySide
  • Internal: pivy
Static Analysis 0
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Marco Laffranchi

Vars main

0.0.2.beta7· FreeCAD Vars

100 / 100

Repository

https://github.com/mnesarco/Vars
main · Created: 2025-05-19 · Updated: 3 mo · 42 python files

Statistics

0
DL(Yr)
0
DL(Mo)
20
Stars
2
Issues
Manifest
Branch
main
Version
0.0.2.beta7
License
LGPL-3.0-or-later
Dependencies 11
  • Compat: PySide6
  • Compat: shiboken2
  • Compat: shiboken6
  • Internal: PySide
  • Internal: pivy
  • Pip: defusedxml
  • Pip: packaging
  • Pip: rich
  • Pip: scour
  • Warn: toml (Not in AddonManager allowed packages)
  • Warn: typer (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Frank David Martínez Muñoz

freecad-xr-workbench main

1.0.2· A Virtual Reality (OpenXR) workbench. View your models with VR goggles.

100 / 100

Repository

https://github.com/kwahoo2/freecad-xr-workbench
main · Created: 2023-07-29 · Updated: 1 mo · 17 python files

Statistics

75
DL(Yr)
0
DL(Mo)
37
Stars
1
Issues
Manifest
Branch
main
Version
1.0.2
License
LGPL-3.0-or-later
Dependencies 10
  • Compat: PySide2
  • Compat: PySide6
  • Compat: shiboken2
  • Compat: shiboken6
  • Internal: Draft
  • Internal: PySide
  • Internal: pivy
  • Pip: PyOpenGL
  • Pip: numpy
  • Warn: xr (Not in AddonManager allowed packages)
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Adrian Przekwas

toSketch main

1.0.1· Tools to help recreate models from STEP files.

100 / 100

Repository

https://github.com/KeithSloan/toSketch
main · Created: 2021-01-02 · Updated: 9 mo · 14 python files

Statistics

2,755
DL(Yr)
0
DL(Mo)
21
Stars
8
Issues
Manifest
Branch
main
Version
1.0.1
License
GPL-2.0-or-later
Dependencies 9
  • Compat: PySide2
  • Internal: Draft
  • Internal: PySide
  • Internal: Sketcher
  • Pip: geomdl
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
  • Warn: Show (Not in AddonManager allowed packages)
Static Analysis 0
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Keith Sloan

yaml-workbench master

0.1.4· A FreeCAD addon that loads and manipulates objects via YAML files.

100 / 100

Repository

https://github.com/Mambix/FreeCAD-yaml-workbench
master · v0.1.4 · Created: 2017-11-26 · Updated: 1 yr · 23 python files

Statistics

0
DL(Yr)
0
DL(Mo)
12
Stars
2
Issues
Manifest
Branch
master
Version
0.1.4
License
LGPL-2.1-or-later
Dependencies 3
  • Internal: Mesh
  • Pip: PyYAML
  • Pip: Requests
Static Analysis 0
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
MambiX Ltd.

sheetmetal master

0.8.24· A simple sheet metal tools workbench for FreeCAD.

99.9 / 100

Repository

https://github.com/shaise/FreeCAD_SheetMetal
master · Last · Created: 2015-06-12 · Updated: 4 d · 36 python files

Statistics

115,711
DL(Yr)
18,421
DL(Mo)
345
Stars
118
Issues
Manifest
Branch
master
Version
0.8.24
License
LGPL-2.1-or-later
Dependencies 6
  • Internal: BOPTools
  • Internal: Draft
  • Internal: PySide
  • Internal: TechDraw
  • Internal: TestApp
  • Pip: networkx
Static Analysis 1
LOW 1
Resources/translations/MonitorCrowdinChanges.py1
  • line 16: Possible hardcoded password: '<enter crowdin token>'
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Shai Seger

MakerWorkbench master

1.0.1· A mechatronic components system + optic components system

99.9 / 100

Repository

https://github.com/URJCMakerGroup/MakerWorkbench
master · Created: 2020-07-24 · Updated: 2 yr · 60 python files

Statistics

3,172
DL(Yr)
347
DL(Mo)
52
Stars
6
Issues
Manifest
Branch
master
Version
1.0.1
License
LGPL-3
Dependencies 4
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: pivy
Static Analysis 1
LOW 1
package.xml1
  • line 11: Icon file 'Resources/icons/Maker_workbench_icon.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
David Muñoz

AssemblyCut main

1.2.0· Cut multiple PartDesign bodies with a single sketch. Auto-detects intersected bodies, supports reordering and per-body Pocket parameters.

99.9 / 100

Repository

https://github.com/cipawow-ship-it/AssemblyCut
main · Created: 2026-07-18 · Updated: 2 mo · 5 python files

Statistics

431
DL(Yr)
264
DL(Mo)
1
Stars
0
Issues
Manifest
Branch
main
Version
1.2.0
License
LGPL-2.1-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 1
LOW 1
package.xml1
  • line 16: Icon file 'Resources/Icons/AssemblyCut.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Cipa

Plot Latest

2026.04.15· Tools to modify existing plots.

99.9 / 100

Repository

https://github.com/FreeCAD/Plot
Latest · Created: 2018-09-22 · Updated: 2 mo · 20 python files

Statistics

0
DL(Yr)
0
DL(Mo)
17
Stars
0
Issues
Manifest
Branch
Latest
Version
2026.04.15
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Dependencies 2
  • Compat: PySide6
  • Pip: matplotlib
Static Analysis 1
LOW 1
package.xml1
  • line 68: Icon file 'freecad/plot/Resources/Icons/Addon.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 4
Jose Luis Cercós Pita PhoneDroid hasecilu looooo

Ratchet main

1.0.0· Workbench to quickly create ratchets.

99.9 / 100

Repository

https://github.com/erroronline1/ratchetWB
main · v1.0.0 · Created: 2022-08-13 · Updated: 6 mo · 27 python files

Statistics

0
DL(Yr)
0
DL(Mo)
5
Stars
0
Issues
Manifest
Branch
main
Version
1.0.0
License
LGPL-3.0-or-later
Dependencies 1
  • Compat: PySide6
Static Analysis 1
LOW 1
package.xml1
  • line 55: Missing icon file 'freecad/Ratchet/Resources/Addon.svg'
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
error on line 1

Solar main

2026.08.22· Workbench to manage solar analysis and configurations.

99.9 / 100

Repository

https://github.com/Francisco-Rosa/Solar
main · Created: 2025-07-13 · Updated: 1 mo · 11 python files

Statistics

0
DL(Yr)
0
DL(Mo)
26
Stars
4
Issues
Manifest
Branch
main
Version
2026.08.22
License
LGPL-2.1-or-later
Dependencies 5
  • Internal: Draft
  • Internal: PySide
  • Warn: ladybug (Not in AddonManager allowed packages)
  • Warn: ladybug_geometry (Not in AddonManager allowed packages)
  • Warn: ladybug_radiance (Not in AddonManager allowed packages)
Static Analysis 1
LOW 1
package.xml1
  • line 85: Icon file 'freecad/Solar/icons/Logo.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Francisco Rosa

HexFill main

1.2.5· Fill any sketch with a honeycomb pattern in one click. Pick a sketch, choose the cell size, and HexFill builds the whole hexagonal grid ...

99.8 / 100

Repository

https://github.com/Clientik/FreeCAD-HexFill
main · v1.2.5 · Created: 2026-06-11 · Updated: 2 mo · 5 python files

Statistics

1,766
DL(Yr)
556
DL(Mo)
11
Stars
2
Issues
Manifest
Branch
main
Version
1.2.5
License
MIT
Dependencies 4
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Internal: pivy
Static Analysis 2
LOW 2
freecad/hexfill/HexFillCommands.py1
  • line 582: Try, Except, Continue detected.
freecad/hexfill/HexFillCore.py1
  • line 450: Try, Except, Continue detected.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Clientik

CadbaseLibrary master

3.0.0· The workbench provides users with an easier way to work with components on the CADBase platform through the FreeCAD interface. Component mod...

99.8 / 100

Repository

https://github.com/mnnxp/cadbaselibrary-freecad
master · v3.0.0 · Created: 2023-02-10 · Updated: 1 yr · 13 python files

Statistics

1,844
DL(Yr)
24
DL(Mo)
8
Stars
0
Issues
Manifest
Branch
master
Version
3.0.0
License
LGPL-3.0-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 2
LOW 2
CadbaseMacro.py2
  • line 26: Consider possible security implications associated with the subprocess module.
  • line 222: subprocess call - check for execution of untrusted input.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
mnnxp

Assembly2MuJoCo main

0.4.0· An addon for exporting FreeCAD builtin Assemblies to MuJoCo.

99.8 / 100

Repository

https://github.com/AnesBenmerzoug/FreeCAD-Assembly2MuJoCo
main · v0.4.0 · Created: 2025-04-19 · Updated: 5 mo · 27 python files

Statistics

87
DL(Yr)
0
DL(Mo)
34
Stars
2
Issues
Manifest
Branch
main
Version
0.4.0
License
LGPL-2.1-or-later
Dependencies 3
  • Internal: Mesh
  • Internal: PySide
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 2
LOW 2
freecad/assembly2mujoco/core/mujoco.py1
  • line 2: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
package.xml1
  • line 17: Icon file 'resources/icons/assembly2mujoco-icon.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Anes Benmerzoug

CamScripts main

V0.0.5 2024/09/25· CamScripts ToolBit import or script creation and configure *every* step of FreeCAD CAM process.

99.8 / 100

Repository

https://github.com/spanner888/CamScripts
main · Created: 2024-08-23 · Updated: 5 mo · 14 python files

Statistics

494
DL(Yr)
0
DL(Mo)
4
Stars
4
Issues
Manifest
Branch
main
Version
V0.0.5 2024/09/25
License
LGPL-2.1-or-later
Dependencies 5
  • Internal: Draft
  • Internal: PySide
  • Pip: Path
  • Pip: numpy
  • Warn: Materials (Not in AddonManager allowed packages)
Static Analysis 2
LOW 2
freecad/cam_scripts/utils.py1
  • line 10: Consider possible security implications associated with the subprocess module.
package.xml1
  • Missing icon declaration
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
spanner888

NikraDAP main

2.0-alpha· Multibody Planar Dynamics Workbench based on a DAP solver algorithm developed by P.E. Nikravesh.

99.8 / 100

Repository

https://github.com/NikraDAP/FreeCAD-NikraDAP
main · Created: 2023-02-22 · Updated: 4 yr · 11 python files

Statistics

0
DL(Yr)
0
DL(Mo)
3
Stars
2
Issues
Manifest
Branch
main
Version
2.0-alpha
License
GPL-3
Dependencies 4
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
  • Pip: scipy
Static Analysis 2
LOW 2
package.xml2
  • line 11: Icon file 'icons/Icon1n.png' is too big (>16kB)
  • line 11: Icon file 'icons/Icon1n.png' is not scalable (svg)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Lukas du Plessis

Design-Proof main

0.1.3· Proof-test your parametric CAD models by systematically varying dimensions and measuring regeneration success rates.

99.7 / 100

Repository

https://github.com/Unai-Pz-de-A/FreeCAD-DesignProof
main · v0.1.3 · Created: 2026-03-30 · Updated: 5 mo · 15 python files

Statistics

0
DL(Yr)
0
DL(Mo)
5
Stars
14
Issues
Manifest
Branch
main
Version
0.1.3
License
LGPL-2.1-or-later
Dependencies 1
  • Compat: PySide6
Static Analysis 3
LOW 3
freecad/DesignProof/core/parameter_detector.py1
  • line 149: Try, Except, Continue detected.
freecad/DesignProof/core/variation_engine.py1
  • line 124: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/DesignProof/ui/analysis_dialog.py1
  • line 293: Starting a process without a shell.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Unai-Pz-de-A

RotaryMoulder main

1.3.1· Design rotary cookie moulder drums. Wraps flat cookie outlines onto a cylindrical drum and cuts drafted cavities, with engraved or embossed ...

99.7 / 100

Repository

https://github.com/mepasschier/FreeCAD-RotaryMoulder
main · Created: 2026-05-20 · Updated: 4 mo · 4 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
main
Version
1.3.1
License
LGPL-2.1-or-later
Dependencies 2
  • Internal: Draft
  • Internal: PySide
Static Analysis 3
LOW 3
freecad/rotary_moulder/geometry.py3
  • line 2124: Try, Except, Continue detected.
  • line 2586: Try, Except, Continue detected.
  • line 2635: Try, Except, Continue detected.
INFO 2
Layout2
  • Uses exec based layout
  • Uses extension based layout
Authors/Maintainers 1
Mike Passchier

ShapeStrings main

0.3.0· Advanced tools for creating and manipulating ShapeStrings.

99.6 / 100

Repository

https://github.com/robertmassaioli/shapestrings
main · v0.3.0 · Created: 2025-12-21 · Updated: 2 mo · 28 python files

Statistics

922
DL(Yr)
257
DL(Mo)
4
Stars
0
Issues
Manifest
Branch
main
Version
0.3.0
License
LGPL-2.1-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 4
LOW 4
bump_version.py4
  • line 20: Consider possible security implications associated with the subprocess module.
  • line 104: subprocess call - check for execution of untrusted input.
  • line 105: Starting a process with a partial executable path
  • line 105: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Robert Massaioli

Motion-Control Latest

1.1.0· Link motion controller to an assembly using OPC UA.

99.6 / 100

Repository

https://github.com/Addon-Shelter/Motion-Control
Latest · Created: 2025-09-25 · Updated: 6 mo · 13 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
Latest
Version
1.1.0
License
GPL-3.0-or-later
Dependencies 3
  • Compat: PySide6
  • Pip: asyncua
  • Warn: aioconsole (Not in AddonManager allowed packages)
Static Analysis 4
LOW 4
Demo/Demo_Cnc/DemoServer/opcserver.py4
  • line 147: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 147: Starting a process with a partial executable path
  • line 190: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 190: Starting a process with a partial executable path
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
PhoneDroid heissgetraenk

freecad.gears master

1.4.0· A gear workbench for FreeCAD

99.5 / 100

Repository

https://github.com/looooo/freecad.gears
master · Created: 2014-04-08 · Updated: 19 d · 53 python files

Statistics

72,675
DL(Yr)
12,471
DL(Mo)
362
Stars
78
Issues
Manifest
Branch
master
Version
1.4.0
License
GPL-3.0-or-later
Dependencies 7
  • Compat: PySide6
  • Internal: Assembly
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
  • Pip: sympy
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 5
LOW 5
freecad/gears/basegear.py1
  • line 155: Try, Except, Continue detected.
scripts/run_visual_tests_xvfb.py3
  • line 14: Consider possible security implications associated with the subprocess module.
  • line 38: Starting a process with a partial executable path
  • line 38: subprocess call - check for execution of untrusted input.
package.xml1
  • line 12: Icon file 'freecad/gears/icons/gearworkbench.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
looooo

DFM main

0.1.21· Design for manufacturing workbench. Evaluate designs against manufacturing processes and associated rules.

99.3 / 100

Repository

https://github.com/ryankembrey/FreeCAD-DFM-Workbench
main · Created: 2025-08-03 · Updated: 17 d · 79 python files

Statistics

2,867
DL(Yr)
676
DL(Mo)
63
Stars
39
Issues
Manifest
Branch
main
Version
0.1.21
License
LGPL-2.1-or-later
Dependencies 5
  • Compat: PySide6
  • Internal: pivy
  • Pip: OCP
  • Pip: PyYAML
  • Pip: gmsh
Static Analysis 7
LOW 7
freecad/DFM/app/contour/measures.py1
  • line 123: Try, Except, Continue detected.
freecad/DFM/app/contour/meshing.py2
  • line 111: Try, Except, Continue detected.
  • line 127: Try, Except, Continue detected.
freecad/DFM/gui/contour/panel.py2
  • line 78: Try, Except, Continue detected.
  • line 84: Try, Except, Continue detected.
freecad/DFM/gui/results/bridge.py1
  • line 228: Try, Except, Continue detected.
package.xml1
  • line 31: Icon file 'resources/icons/logo.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Ryan Kembrey

BillOfMaterials main

1.3.3· A workbench to create Bill of Materials (BoM) independent of the assembly workbench of your choice.

99.2 / 100

Repository

https://github.com/APEbbers/BillOfMaterials-WB
main · Created: 2023-11-05 · Updated: 5 d · 36 python files

Statistics

7,994
DL(Yr)
1,073
DL(Mo)
34
Stars
4
Issues
Manifest
Branch
main
Version
1.3.3
License
LGPL-3.0-or-later
Dependencies 4
  • Internal: PySide
  • Pip: defusedxml
  • Pip: matplotlib
  • Pip: openpyxl
Static Analysis 8
LOW 8
GetBOM_BIM.py2
  • line 179: Try, Except, Continue detected.
  • line 185: Try, Except, Continue detected.
Standard_Functions_BOM_WB.py5
  • line 287: Consider possible security implications associated with the subprocess module.
  • line 294: subprocess call - check for execution of untrusted input.
  • line 296: Starting a process without a shell.
  • line 300: Starting a process with a partial executable path
  • line 300: subprocess call - check for execution of untrusted input.
package.xml1
  • line 26: Icon file 'Resources/Icons/BillOfMaterialsWB.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

IDF Latest

1.0.0· Importer for IDF files.

99 / 100

Repository

https://github.com/FreeCAD/IDF
Latest · Created: 2026-03-07 · Updated: 7 mo · 12 python files

Statistics

0
DL(Yr)
0
DL(Mo)
1
Stars
2
Issues
Manifest
Branch
Latest
Version
1.0.0
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Static Analysis 1
MEDIUM 1
freecad/IDF/Constants.py1
  • line 20: Probable insecure usage of temp file/directory.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
Milos Koutny PhoneDroid

Nodes main

0.1.36· Visual scripting workbench for FreeCAD

99 / 100

Repository

https://github.com/j8sr0230/Nodes
main · Created: 2022-08-10 · Updated: 2 yr · 110 python files

Statistics

0
DL(Yr)
0
DL(Mo)
120
Stars
14
Issues
Manifest
Branch
main
Version
0.1.36
License
LGPL-2.1-or-later
Dependencies 6
  • Internal: Mesh
  • Pip: awkward
  • Pip: blinker
  • Pip: numpy
  • Pip: qtpy
  • Pip: scipy
Static Analysis 1
MEDIUM 1
nodes/script/script_py_script.py1
  • line 105: Use of exec detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Ronny Scharf-Wildenhain

Curves main

0.6.81· A collection of tools mainly dedicated to NURBS curves and surfaces modeling.

98.9 / 100

Repository

https://github.com/tomate44/CurvesWB
main · Created: 2016-08-06 · Updated: 1 d · 120 python files

Statistics

105,678
DL(Yr)
15,664
DL(Mo)
155
Stars
33
Issues
Manifest
Branch
main
Version
0.6.81
License
LGPL-2.1-or-later, Apache-2.0
Dependencies 8
  • Internal: BOPTools
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: defusedxml
  • Pip: numpy
  • Pip: scipy
  • Warn: splipy (Not in AddonManager allowed packages)
Static Analysis 2
MEDIUM 1
freecad/Curves/pasteSVG.py1
  • line 38: Using xml.sax.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 1
freecad/Curves/pasteSVG.py1
  • line 16: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Christophe Grellier

free2ki freecad-addons

1.1.2· Export your 3D models to VRML files, with correctly applied rotation and scaling, for use in KiCad as well as Blender.

98.9 / 100

Repository

https://github.com/30350n/free2ki
freecad-addons · v1.1.2 · Created: 2022-01-09 · Updated: 9 mo · 6 python files

Statistics

282
DL(Yr)
0
DL(Mo)
59
Stars
0
Issues
Manifest
Branch
freecad-addons
Version
1.1.2
License
GPL-3.0-or-later
Dependencies 4
  • Compat: PySide6
  • Internal: PySide
  • Pip: Pillow
  • Pip: numpy
Static Analysis 2
MEDIUM 1
.github/workflows/build_freecad_package.py1
  • line 23: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 1
.github/workflows/build_freecad_package.py1
  • line 7: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
30350n

Detessellate main

1.2.0· FreeCAD workbench of tools to reverse engineer meshes

98.7 / 100

Repository

https://github.com/DesignWeaver3D/Detessellate
main · Created: 2025-11-22 · Updated: 21 d · 23 python files

Statistics

3,712
DL(Yr)
1,088
DL(Mo)
98
Stars
7
Issues
Manifest
Branch
main
Version
1.2.0
License
LGPL-2.1-or-later
Dependencies 6
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: numpy
Static Analysis 4
MEDIUM 1
freecad/Detessellate/PointPlaneSketch.py1
  • line 980: Possible SQL injection vector through string-based query construction.
LOW 3
freecad/Detessellate/CoplanarSketch.py1
  • line 353: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/Detessellate/SketcherWireDoctor_Main.py1
  • line 234: Try, Except, Continue detected.
package.xml1
  • line 38: Icon file 'freecad/Detessellate/Resources/Icons/Detessellate.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
DesignWeaver3D

WB_Organizer main

2024.1.29· A workbench organizer widget for FreeCAD. Allows you to group your long list of workbenches into smaller meaningful groups. Allows you to re...

98.6 / 100

Repository

https://github.com/Palmstroemen/WB_Organizer
main · Created: 2024-01-26 · Updated: 3 yr · 3 python files

Statistics

3,267
DL(Yr)
369
DL(Mo)
6
Stars
5
Issues
Manifest
Branch
main
Version
2024.1.29
License
LGPL-2.1-or-later
Dependencies 1
  • Compat: PySide2
Static Analysis 14
LOW 14
WBO_Gui.py7
  • line 516: Consider possible security implications associated with the subprocess module.
  • line 523: Starting a process with a partial executable path
  • line 523: subprocess call - check for execution of untrusted input.
  • line 525: Starting a process with a partial executable path
  • line 525: subprocess call - check for execution of untrusted input.
  • line 527: Starting a process with a partial executable path
  • line 527: subprocess call - check for execution of untrusted input.
WBO_Preferences.py7
  • line 23: Consider possible security implications associated with the subprocess module.
  • line 30: Starting a process with a partial executable path
  • line 30: subprocess call - check for execution of untrusted input.
  • line 32: Starting a process with a partial executable path
  • line 32: subprocess call - check for execution of untrusted input.
  • line 34: Starting a process with a partial executable path
  • line 34: subprocess call - check for execution of untrusted input.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Palmstroemen

FreeCAD-Beginner-Assistant main

1.0· Best practices modeling assistant for the Part and Sketcher workbench.

98.5 / 100

Repository

https://github.com/alekssadowski95/FreeCAD-Beginner-Assistant
main · Created: 2023-12-12 · Updated: 2 yr · 37 python files

Statistics

253
DL(Yr)
18
DL(Mo)
18
Stars
6
Issues
Manifest
Branch
main
Version
1.0
License
LGPL-2.1-or-later
Dependencies 9
  • Internal: Sketcher
  • Pip: Pillow
  • Pip: cryptography
  • Pip: defusedxml
  • Pip: fontTools
  • Warn: endesive (Not in AddonManager allowed packages)
  • Warn: pymemtrace (Not in AddonManager allowed packages)
  • Warn: pympler (Not in AddonManager allowed packages)
  • Warn: uharfbuzz (Not in AddonManager allowed packages)
Static Analysis 6
MEDIUM 1
fpdf/encryption.py1
  • line 526: Use of insecure cipher mode cryptography.hazmat.primitives.ciphers.modes.ECB.
LOW 5
pdfgen.py4
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 191: subprocess call - check for execution of untrusted input.
  • line 193: Starting a process without a shell.
  • line 195: subprocess call - check for execution of untrusted input.
package.xml1
  • line 13: Missing icon file 'Icons/FreeCAD-Beginner-Assistant.svg'
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 3
Elizabeth Harasymiw Aleksander Sadowski(https://github.com/alekssadowski95/FreeCAD-Beginner-Assistant) Aleksander Sadowski

ToolSeek main

0.3.1· Type-to-find FreeCAD commands (command palette). Default shortcut: Ctrl+Space.

98.3 / 100

Repository

https://github.com/robdevtech/ToolSeek
main · v0.3.1 · Created: 2026-08-11 · Updated: 2 mo · 15 python files

Statistics

0
DL(Yr)
0
DL(Mo)
5
Stars
2
Issues
Manifest
Branch
main
Version
0.3.1
License
LGPL-2.1-or-later, CC-BY-4.0
Dependencies 7
  • Compat: PySide2
  • Compat: PySide6
  • Compat: shiboken2
  • Compat: shiboken6
  • Internal: PySide
  • Warn: shiboken (Not in AddonManager allowed packages)
  • Warn: sip (Not in AddonManager allowed packages)
Static Analysis 8
MEDIUM 1
freecad/ToolSeek/shortcut_edit.py1
  • line 172: Use of extra potential SQL attack vector.
LOW 7
freecad/ToolSeek/bootstrap.py2
  • line 220: Try, Except, Continue detected.
  • line 743: Try, Except, Continue detected.
freecad/ToolSeek/shortcut_conflicts.py5
  • line 144: Try, Except, Continue detected.
  • line 151: Try, Except, Continue detected.
  • line 160: Try, Except, Continue detected.
  • line 297: Try, Except, Continue detected.
  • line 329: Try, Except, Continue detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
therobdev

stepParts main

0.1.1· Search the step.parts online catalog of open STEP CAD parts and insert results directly into the active document.

98 / 100

Repository

https://github.com/iplayfast/stepParts
main · v0.1.1 · Created: 2026-07-31 · Updated: 2 mo · 4 python files

Statistics

0
DL(Yr)
0
DL(Mo)
1
Stars
0
Issues
Manifest
Branch
main
Version
0.1.1
License
LGPL-2.1-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 2
MEDIUM 2
freecad/stepParts/api_client.py2
  • line 58: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 180: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Chris Bruner

frame master

0.1.1· A workbench for beams and frames

97.9 / 100

Repository

https://github.com/looooo/freecad_frame
master · Created: 2015-11-23 · Updated: 2 mo · 26 python files

Statistics

5,198
DL(Yr)
717
DL(Mo)
27
Stars
11
Issues
Manifest
Branch
master
Version
0.1.1
License
LGPL-2.1-or-later
Dependencies 7
  • Internal: PySide
  • Internal: pivy
  • Pip: PyYAML
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 3
MEDIUM 2
freecad/frametools/fem2d.py1
  • line 31: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
setup.py1
  • line 7: Use of exec detected.
LOW 1
freecad/frametools/image_tools.py1
  • line 964: Try, Except, Continue detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
looooo

CarteGrid main

1.3.1· Generate and batch-export multiple variations of a parametric model, to whatever format FreeCAD can produce. Define a parameter grid ove...

97.9 / 100

Repository

https://github.com/MarcBresson/CarteGrid
main · Created: 2026-07-09 · Updated: 25 d · 42 python files

Statistics

0
DL(Yr)
0
DL(Mo)
3
Stars
2
Issues
Manifest
Branch
main
Version
1.3.1
License
MIT
Dependencies 2
  • Internal: PySide
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 3
MEDIUM 2
docs/conf.py1
  • line 14: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
tests/test_config.py1
  • line 126: Probable insecure usage of temp file/directory.
LOW 1
docs/conf.py1
  • line 3: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Marc Bresson

MnesarcoUtils main

0.2.16· A collection of tools mainly dedicated to scripting and experiments.

97.8 / 100

Repository

https://github.com/mnesarco/FreeCAD_Utils
main · Created: 2021-01-18 · Updated: 6 mo · 65 python files

Statistics

0
DL(Yr)
0
DL(Mo)
19
Stars
1
Issues
Manifest
Branch
main
Version
0.2.16
License
GPL-3.0
Dependencies 4
  • Internal: Draft
  • Internal: PySide
  • Internal: pivy
  • Warn: pyserial (Not in AddonManager allowed packages)
Static Analysis 4
MEDIUM 2
freecad/mnesarco/scripts/script.py1
  • line 109: Use of exec detected.
freecad/mnesarco/svg/parser.py1
  • line 76: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 2
freecad/mnesarco/svg/parser.py2
  • line 22: Using ContentHandler to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ContentHandler with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 23: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Frank Martinez

pyOpToolsWorkbench master

0.0.5· An optics ray-tracing workbench based on pyOpTools

97.8 / 100

Repository

https://github.com/cihologramas/freecad-pyoptools
master · Created: 2017-07-06 · Updated: 4 d · 81 python files

Statistics

0
DL(Yr)
0
DL(Mo)
26
Stars
4
Issues
Manifest
Branch
master
Version
0.0.5
License
GPL-3.0-or-later
Dependencies 6
  • Internal: PySide
  • Internal: pivy
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 4
MEDIUM 2
setup.py1
  • line 10: Use of exec detected.
version.py1
  • line 7: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 2
version.py1
  • line 2: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
package.xml1
  • line 12: Icon file 'freecad/pyoptools/resources/pyoptools.png' is not scalable (svg)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Ricardo Amézquita Orozco

Cables master

0.3.7· Electrical cables drawing tools workbench for FreeCAD.

97.7 / 100

Repository

https://github.com/sargo-devel/Cables
master · v0.3.7 · Created: 2025-01-21 · Updated: 2 mo · 33 python files

Statistics

16,279
DL(Yr)
2,319
DL(Mo)
99
Stars
9
Issues
Manifest
Branch
master
Version
0.3.7
License
LGPL-3.0-or-later
Dependencies 7
  • Internal: Arch
  • Internal: Draft
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Warn: Show (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 5
MEDIUM 2
freecad/cables/resources/translations/updateTranslations.py2
  • line 171: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 223: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 3
freecad/cables/resources/translations/updateTranslations.py3
  • line 64: Consider possible security implications associated with the subprocess module.
  • line 289: subprocess call - check for execution of untrusted input.
  • line 352: subprocess call - check for execution of untrusted input.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
SargoDevel

HistoryWorkbench release

0.2.0· Easy version control for FreeCAD: track document history and review changes using 3D and tree comparisons.

97.7 / 100

Repository

https://github.com/eblanshey/HistoryWorkbench
release · Created: 2026-05-05 · Updated: 13 d · 320 python files

Statistics

1,349
DL(Yr)
612
DL(Mo)
155
Stars
4
Issues
Manifest
Branch
release
Version
0.2.0
License
LGPL-2.1-or-later
Dependencies 5
  • Compat: PySide6
  • Internal: PySide
  • Internal: Sketcher
  • Pip: PyYAML
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 14
MEDIUM 1
freecad/history_wb/infrastructure/persistence/snapshot_yaml.py1
  • line 21: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
LOW 13
freecad/history_wb/infrastructure/git/git_port_adapter.py3
  • line 9: Consider possible security implications associated with the subprocess module.
  • line 112: subprocess call - check for execution of untrusted input.
  • line 754: subprocess call - check for execution of untrusted input.
scripts/dev-metrics.py2
  • line 19: Consider possible security implications associated with the subprocess module.
  • line 43: subprocess call - check for execution of untrusted input.
scripts/prepare_release.py3
  • line 9: Consider possible security implications associated with the subprocess module.
  • line 33: Starting a process with a partial executable path
  • line 33: subprocess call - check for execution of untrusted input.
tests/unit/infrastructure/git/test_get_committed_files.py1
  • line 6: Consider possible security implications associated with the subprocess module.
tests/unit/infrastructure/git/test_get_dirty_files.py1
  • line 6: Consider possible security implications associated with the subprocess module.
tests/unit/infrastructure/git/test_git_port_adapter.py1
  • line 7: Consider possible security implications associated with the subprocess module.
tests/unit/infrastructure/git/test_git_port_adapter_commit.py1
  • line 6: Consider possible security implications associated with the subprocess module.
tests/unit/infrastructure/git/test_git_port_adapter_restore.py1
  • line 4: Consider possible security implications associated with the subprocess module.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Ephi Blanshey

cadquery_module master

2.2.0· Build CadQuery models withing FreeCAD.

97.7 / 100

Repository

https://github.com/CadQuery/cadquery-freecad-workbench
master · Created: 2014-11-22 · Updated: 3 mo · 11 python files

Statistics

464
DL(Yr)
0
DL(Mo)
151
Stars
5
Issues
Manifest
Branch
master
Version
2.2.0
License
Apache-2.0
Dependencies 4
  • Compat: PySide6
  • Internal: PySide
  • Pip: build123d
  • Pip: cadquery
Static Analysis 23
LOW 21
freecad/CadQuery/Command.py23
  • line 27: Consider possible security implications associated with the subprocess module.
  • line 29: Starting a process with a partial executable path
  • line 29: subprocess call - check for execution of untrusted input.
  • line 30: Starting a process with a partial executable path
  • line 30: subprocess call - check for execution of untrusted input.
  • line 50: Consider possible security implications associated with the subprocess module.
  • line 51: Starting a process with a partial executable path
  • line 51: subprocess call - check for execution of untrusted input.
  • line 52: Starting a process with a partial executable path
  • line 52: subprocess call - check for execution of untrusted input.
  • line 53: Starting a process with a partial executable path
  • line 53: subprocess call - check for execution of untrusted input.
  • line 54: Starting a process with a partial executable path
  • line 54: subprocess call - check for execution of untrusted input.
  • line 55: Starting a process with a partial executable path
  • line 55: subprocess call - check for execution of untrusted input.
  • line 56: Starting a process with a partial executable path
  • line 56: subprocess call - check for execution of untrusted input.
  • line 75: Consider possible security implications associated with the subprocess module.
  • line 77: Starting a process with a partial executable path
  • … 3 more issues
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Jeremy Wright

freecad-wakatime main

0.6.0· A simple FreeCAD WakaTime extension.

97.6 / 100

Repository

https://github.com/Pegoku/freecad-wakatime
main · Created: 2025-01-05 · Updated: 3 mo · 6 python files

Statistics

0
DL(Yr)
0
DL(Mo)
4
Stars
2
Issues
Manifest
Branch
main
Version
0.6.0
License
LGPL-2.1-or-later
Static Analysis 6
MEDIUM 2
freecad/Wakatime/scripts/logWaka.py2
  • line 167: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 176: Chmod setting a permissive mask 0o755 on file (dst).
LOW 4
freecad/Wakatime/scripts/logWaka.py4
  • line 46: Consider possible security implications associated with the subprocess module.
  • line 118: subprocess call - check for execution of untrusted input.
  • line 135: Consider possible security implications associated with the subprocess module.
  • line 185: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Pegoku

Ship master

2024.11.26· Naval ship design (architecture, seakeeping, and ship resistance)

97.4 / 100

Repository

https://github.com/FreeCAD/freecad.ship
master · Created: 2018-11-08 · Updated: 1 yr · 71 python files

Statistics

1,043
DL(Yr)
148
DL(Mo)
58
Stars
6
Issues
Manifest
Branch
master
Version
2024.11.26
License
LGPL-2.1-or-later
Dependencies 8
  • Internal: PySide
  • Internal: Spreadsheet
  • Pip: capytaine
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
  • Pip: xarray
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 8
MEDIUM 2
freecad/ship/shipUtils/Serialize.py1
  • line 46: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
setup.py1
  • line 8: Use of exec detected.
LOW 6
freecad/ship/Instance.py1
  • line 330: Try, Except, Continue detected.
freecad/ship/TankInstance.py1
  • line 140: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/ship/shipHydrostatics/TaskPanel.py1
  • line 384: Try, Except, Continue detected.
freecad/ship/shipHydrostatics/Tools.py1
  • line 146: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/ship/shipUtils/Serialize.py1
  • line 1: Consider possible security implications associated with pickle module.
package.xml1
  • line 13: Icon file 'freecad/ship/resources/icons/Ship_Logo.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Jose Luis Cercós Pita

Quetzal master

1.8.11· A set of commands and objects that help to speed-up the drawing of frames and pipelines. Dodo successor.

97.3 / 100

Repository

https://github.com/EdgarJRobles/quetzal
master · Created: 2020-05-03 · Updated: 1 mo · 28 python files

Statistics

8,826
DL(Yr)
964
DL(Mo)
34
Stars
20
Issues
Manifest
Branch
master
Version
1.8.11
License
LGPL-3.0-or-later
Dependencies 8
  • Compat: PySide2
  • Internal: Arch
  • Internal: BOPTools
  • Internal: Draft
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
  • Pip: typing_extensions
Static Analysis 9
MEDIUM 2
translationz/update_crowdin.py2
  • line 173: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 254: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 7
pCmd.py1
  • line 461: Try, Except, Continue detected.
pFeatures.py1
  • line 1176: Try, Except, Continue detected.
translationz/update_crowdin.py5
  • line 75: Consider possible security implications associated with the subprocess module.
  • line 408: subprocess call - check for execution of untrusted input.
  • line 409: subprocess call - check for execution of untrusted input.
  • line 410: subprocess call - check for execution of untrusted input.
  • line 414: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 6
Edgar Robles triplus microelly looo Edgar J Robles Riccardo Treu (oddtopus)

NeoRibbon master

0.3.6· Lightweight ribbon UI for FreeCAD 1.1+. Maps the active workbench toolbars into a compact top ribbon, hides classic toolbars while enabled, ...

97.3 / 100

Repository

https://github.com/robdevtech/NeoRibbon
master · Created: 2026-08-09 · Updated: 1 mo · 20 python files

Statistics

271
DL(Yr)
271
DL(Mo)
6
Stars
1
Issues
Manifest
Branch
master
Version
0.3.6
License
LGPL-2.1-or-later, LGPL-2.1-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 9
MEDIUM 2
freecad/NeoRibbon/prefs.py1
  • line 57: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
freecad/NeoRibbon/shortcut_edit.py1
  • line 148: Use of extra potential SQL attack vector.
LOW 7
freecad/NeoRibbon/prefs.py4
  • line 8: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 90: Try, Except, Continue detected.
  • line 147: Try, Except, Continue detected.
  • line 529: Try, Except, Continue detected.
freecad/NeoRibbon/ribbon_bar.py1
  • line 668: Try, Except, Continue detected.
freecad/NeoRibbon/shortcut_conflicts.py2
  • line 149: Try, Except, Continue detected.
  • line 188: Try, Except, Continue detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Rob

FrameForge main

0.2.1· FrameForge is dedicated for creating Frames and Beams, and apply operations (miter cuts, trim cuts) on these profiles.

97 / 100

Repository

https://github.com/lukh/frameforge
main · v0.2.1 · Created: 2024-10-07 · Updated: 6 mo · 25 python files

Statistics

11,210
DL(Yr)
1,143
DL(Mo)
38
Stars
37
Issues
Manifest
Branch
main
Version
0.2.1
License
LGPL-3.0-only
Dependencies 5
  • Internal: Assembly
  • Internal: BOPTools
  • Internal: PySide
  • Internal: pivy
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 3
MEDIUM 3
freecad/frameforge/_utils.py2
  • line 43: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 63: Use of possibly insecure function - consider using safer ast.literal_eval.
setup.py1
  • line 7: Use of exec detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Vivien Henry

ExplodedAssembly

No description

97 / 100

Repository

https://github.com/JMG1/ExplodedAssembly
master · Created: 2016-03-13 · Updated: 3 yr · 4 python files

Statistics

4,425
DL(Yr)
635
DL(Mo)
140
Stars
24
Issues
Dependencies 1
  • Internal: pivy
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

AirPlaneDesign master

0.4.1· A FreeCAD workbench dedicated to Airplane Design.

97 / 100

Repository

https://github.com/FredsFactory/FreeCAD_AirPlaneDesign
master · Created: 2018-06-11 · Updated: 10 mo · 19 python files

Statistics

5,190
DL(Yr)
597
DL(Mo)
118
Stars
9
Issues
Manifest
Branch
master
Version
0.4.1
License
LGPL-2.1
Dependencies 3
  • Internal: Draft
  • Internal: PySide
  • Pip: numpy
Static Analysis 1
HIGH 1
package.xml1
  • line 2: Expecting a namespace for element package
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
FredsFactory

ProDarkThemePreferencePack main

1.0.0· ProDark preference pack including a stylesheet and othe GUI colour information for a complete ProDark experience

97 / 100

Repository

https://github.com/turn211/ProDarkThemePreferencePack
main · Created: 2022-05-17 · Updated: 3 yr · 0 python files

Statistics

5,124
DL(Yr)
517
DL(Mo)
8
Stars
0
Issues
Manifest
Branch
main
Version
1.0.0
License
GPL-2.0-or-later
Static Analysis 1
HIGH 1
package.xml1
  • line 7: Element maintainer failed to validate attributes
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
turn211

ArchTextures

No description

97 / 100

Repository

https://github.com/furti/FreeCAD-ArchTextures
master · Created: 2018-09-30 · Updated: 5 yr · 23 python files

Statistics

2,919
DL(Yr)
415
DL(Mo)
35
Stars
23
Issues
Dependencies 3
  • Compat: PySide2
  • Internal: PySide
  • Internal: pivy
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

CommandPanel

No description

97 / 100

Repository

https://github.com/triplus/CommandPanel
master · Created: 2017-06-30 · Updated: 8 yr · 10 python files

Statistics

0
DL(Yr)
0
DL(Mo)
3
Stars
1
Issues
Dependencies 1
  • Internal: PySide
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

CubeMenu

No description

97 / 100

Repository

https://github.com/triplus/CubeMenu
master · Created: 2020-02-08 · Updated: 6 yr · 8 python files

Statistics

0
DL(Yr)
0
DL(Mo)
6
Stars
1
Issues
Dependencies 1
  • Internal: PySide
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

IconThemes

No description

97 / 100

Repository

https://github.com/triplus/IconThemes
master · Created: 2016-10-10 · Updated: 6 yr · 3 python files

Statistics

485
DL(Yr)
0
DL(Mo)
22
Stars
8
Issues
Dependencies 1
  • Internal: PySide
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

Pyramids-and-Polyhedrons Latest

0.2.2· Create various polyhedrons in the Part workbench.

97 / 100

Repository

https://github.com/Addon-Shelter/Polyhedra
Stable · v0.2.2 · Created: 2025-09-14 · Updated: 6 mo · 32 python files

Statistics

979
DL(Yr)
0
DL(Mo)
1
Stars
0
Issues
Manifest
Branch
Latest
Version
0.2.2
License
GPL-3.0-or-later, CC-BY-SA-4.0, Unlicense
Dependencies 1
  • Compat: PySide6
Static Analysis 1
HIGH 1
package.xml1
  • Declared branch 'Latest' does not match git branch 'Stable'
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
Eddy Verlinden PhoneDroid

SelectorToolbar

No description

97 / 100

Repository

https://github.com/triplus/SelectorToolbar
master · Created: 2017-03-18 · Updated: 7 yr · 2 python files

Statistics

0
DL(Yr)
0
DL(Mo)
8
Stars
3
Issues
Dependencies 1
  • Internal: PySide
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

TabBar

No description

97 / 100

Repository

https://github.com/triplus/TabBar
master · Created: 2016-01-09 · Updated: 8 yr · 2 python files

Statistics

0
DL(Yr)
0
DL(Mo)
8
Stars
1
Issues
Dependencies 1
  • Internal: PySide
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

ToolbarStyle

No description

97 / 100

Repository

https://github.com/triplus/ToolbarStyle
master · Created: 2018-01-31 · Updated: 8 yr · 3 python files

Statistics

0
DL(Yr)
0
DL(Mo)
3
Stars
0
Issues
Dependencies 1
  • Internal: PySide
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

ose-piping

No description

97 / 100

Repository

https://github.com/rkrenzler/ose-piping-workbench
master · Created: 2018-02-17 · Updated: 4 yr · 35 python files

Statistics

0
DL(Yr)
0
DL(Mo)
13
Stars
6
Issues
Dependencies 2
  • Internal: PySide
  • Warn: pCmd (Not in AddonManager allowed packages)
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

pivy_trackers

No description

97 / 100

Repository

https://github.com/joelgraff/pivy_trackers
master · Created: 2019-09-19 · Updated: 7 yr · 61 python files

Statistics

0
DL(Yr)
0
DL(Mo)
23
Stars
6
Issues
Dependencies 2
  • Internal: PySide
  • Internal: pivy
Static Analysis 1
HIGH 1
package.xml1
  • File not found.
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 0

yaml-workbench master

0.1.4· A FreeCAD addon that loads and manipulates objects via YAML files.

97 / 100

Repository

https://github.com/Mambix/FreeCAD-yaml-workbench
v0.1.4 · v0.1.4 · Created: 2017-11-26 · Updated: 1 yr · 23 python files

Statistics

0
DL(Yr)
0
DL(Mo)
12
Stars
2
Issues
Manifest
Branch
master
Version
0.1.4
License
LGPL-2.1-or-later
Dependencies 3
  • Internal: Mesh
  • Pip: PyYAML
  • Pip: Requests
Static Analysis 1
HIGH 1
package.xml1
  • Declared branch 'master' does not match git branch 'v0.1.4'
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
MambiX Ltd.

MeshRemodel master

1.12.0· Workbench for remodeling and repairing mesh objects.

96.9 / 100

Repository

https://github.com/mwganson/MeshRemodel
master · Created: 2019-08-18 · Updated: 28 d · 10 python files

Statistics

7,664
DL(Yr)
1,590
DL(Mo)
35
Stars
0
Issues
Manifest
Branch
master
Version
1.12.0
License
LGPL-2.1-or-later
Dependencies 7
  • Compat: PySide6
  • Compat: shiboken6
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Pip: Requests
  • Pip: numpy
Static Analysis 4
MEDIUM 3
freecad/Mesh_Remodel/MeshRemodelCmd.py1
  • line 1312: Possible SQL injection vector through string-based query construction.
freecad/Mesh_Remodel/Workbench.py2
  • line 101: Call to requests without timeout
  • line 105: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 1
freecad/Mesh_Remodel/Workbench.py1
  • line 95: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Mark Ganson

Defeaturing master

1.3.2· A set of tools to edit a Shape or a STEP model.

96.9 / 100

Repository

https://github.com/easyw/Defeaturing_WB
master · Created: 2018-07-02 · Updated: 4 mo · 8 python files

Statistics

8,760
DL(Yr)
1,078
DL(Mo)
39
Stars
8
Issues
Manifest
Branch
master
Version
1.3.2
License
AGPLv3.0
Dependencies 3
  • Internal: Draft
  • Internal: PySide
  • Pip: Path
Static Analysis 2
HIGH 1
package.xml1
  • line 7: Missing license file 'LICENSE'
LOW 1
license.*1
  • File not found.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Maui

Plot Latest

2026.04.15· Tools to modify existing plots.

96.9 / 100

Repository

https://github.com/FreeCAD/Plot
Stable · Created: 2018-09-22 · Updated: 6 mo · 20 python files

Statistics

2,035
DL(Yr)
326
DL(Mo)
17
Stars
0
Issues
Manifest
Branch
Latest
Version
2026.04.15
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Dependencies 2
  • Compat: PySide6
  • Pip: matplotlib
Static Analysis 2
HIGH 1
package.xml1
  • Declared branch 'Latest' does not match git branch 'Stable'
LOW 1
package.xml1
  • line 68: Icon file 'freecad/plot/Resources/Icons/Addon.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 4
Jose Luis Cercós Pita PhoneDroid hasecilu looooo

dxf-library

No description

96.9 / 100

Repository

https://github.com/yorikvanhavre/Draft-dxf-importer
master · Created: 2013-06-22 · Updated: 3 yr · 4 python files

Statistics

2,194
DL(Yr)
242
DL(Mo)
73
Stars
4
Issues
Static Analysis 2
HIGH 1
package.xml1
  • File not found.
LOW 1
license.*1
  • File not found.
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 0

taack-plm-freecad main

2026.10.04· This workbench contains tools to interact with Taack Plm Intranet server app you can find under the https://github.com/Taack/plm

96.9 / 100

Repository

https://github.com/Taack/taack-plm-freecad
main · Created: 2023-02-09 · Updated: today · 4 python files

Statistics

33
DL(Yr)
33
DL(Mo)
16
Stars
1
Issues
Manifest
Branch
main
Version
2026.10.04
License
LGPL-2.1-or-later
Dependencies 3
  • Internal: PySide
  • Pip: Requests
  • Pip: protobuf
Static Analysis 2
HIGH 1
Intranet.py1
  • line 208: Use of weak SHA1 hash for security. Consider usedforsecurity=False
LOW 1
Intranet.py1
  • line 44: Possible hardcoded password: ''
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Adrien GUICHARD

Plot Latest

2025.10.29· Tools to modify existing plots.

96.9 / 100

Repository

https://github.com/FreeCAD/Plot
2025.10.29 · 2025.10.29 · Created: 2018-09-22 · Updated: 11 mo · 23 python files

Statistics

0
DL(Yr)
0
DL(Mo)
17
Stars
0
Issues
Manifest
Branch
Latest
Version
2025.10.29
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Dependencies 2
  • Compat: PySide6
  • Pip: matplotlib
Static Analysis 2
HIGH 1
package.xml1
  • Declared branch 'Latest' does not match git branch '2025.10.29'
LOW 1
package.xml1
  • line 65: Icon file 'freecad/plot/Resources/Icons/Addon.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 4
Jose Luis Cercós Pita PhoneDroid hasecilu looooo

symbols_library

No description

96.9 / 100

Repository

https://github.com/FreeCAD/FreeCAD-symbols
master · Created: 2015-04-21 · Updated: 5 mo · 0 python files

Statistics

1,290
DL(Yr)
0
DL(Mo)
39
Stars
0
Issues
Static Analysis 2
HIGH 1
package.xml1
  • File not found.
LOW 1
license.*1
  • File not found.
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 0

addFC main

3.7.8· Additional tools for FreeCAD.

96.8 / 100

Repository

https://github.com/GS90/addFC
main · Created: 2024-05-12 · Updated: 2 mo · 21 python files

Statistics

11,795
DL(Yr)
926
DL(Mo)
52
Stars
1
Issues
Manifest
Branch
main
Version
3.7.8
License
LGPL-2.1-or-later
Dependencies 7
  • Internal: Arch
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Pip: ezdxf
  • Pip: numpy
  • Warn: stepZ (Not in AddonManager allowed packages)
Static Analysis 14
MEDIUM 2
addon/addFC/Preference.py1
  • line 101: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
addon/addFC/toolkit/Library.py1
  • line 401: Use of extra potential SQL attack vector.
LOW 12
addon/addFC/Other.py9
  • line 26: Consider possible security implications associated with the subprocess module.
  • line 64: Starting a process with a partial executable path
  • line 64: subprocess call - check for execution of untrusted input.
  • line 65: Starting a process with a partial executable path
  • line 65: subprocess call - check for execution of untrusted input.
  • line 66: Starting a process with a partial executable path
  • line 66: subprocess call - check for execution of untrusted input.
  • line 144: Starting a process with a partial executable path
  • line 144: subprocess call - check for execution of untrusted input.
addon/addFC/Preference.py3
  • line 30: Consider possible security implications associated with the subprocess module.
  • line 32: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 123: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Golodnikov Sergey

ConstraintDesign main

beta-0.1· This addon adds a design workbench that is specially designed to be as flexible and stable as possible.

96.8 / 100

Repository

https://github.com/drwho495/ConstraintDesign-wb
main · Created: 2025-04-13 · Updated: 6 d · 47 python files

Statistics

2,283
DL(Yr)
54
DL(Mo)
15
Stars
16
Issues
Manifest
Branch
main
Version
beta-0.1
License
LGPL-2.1-only
Dependencies 2
  • Internal: PySide
  • Internal: pivy
Static Analysis 3
HIGH 1
Layout1
  • Invalid __init__.py file in root. Change to Init.py
LOW 2
Entities/Extrusion.py1
  • line 659: Try, Except, Continue detected.
Utils/Utils.py1
  • line 254: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
drwho495

Cubinets main

0.1.0-demo· Visualize cabinet assemblies using parametric templates and generate cut lists.

96.8 / 100

Repository

https://github.com/foreachidea/Cubinets
stable · Created: 2026-02-20 · Updated: 6 mo · 28 python files

Statistics

0
DL(Yr)
0
DL(Mo)
3
Stars
0
Issues
Manifest
Branch
main
Version
0.1.0-demo
License
GPL-3.0-or-later
Dependencies 2
  • Compat: PySide6
  • Internal: PySide
Static Analysis 3
HIGH 1
package.xml1
  • Declared branch 'main' does not match git branch 'stable'
LOW 2
freecad/Cubinets/File.py1
  • line 68: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
package.xml1
  • line 65: Icon file 'freecad/Cubinets/Resources/Icons/Addon.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Vytautas Rimkevicius

Cubinets main

0.1.0-demo· Visualize cabinet assemblies using parametric templates and generate cut lists.

96.8 / 100

Repository

https://github.com/foreachidea/Cubinets
latest · Created: 2026-02-20 · Updated: 6 mo · 28 python files

Statistics

0
DL(Yr)
0
DL(Mo)
3
Stars
0
Issues
Manifest
Branch
main
Version
0.1.0-demo
License
GPL-3.0-or-later
Dependencies 2
  • Compat: PySide6
  • Internal: PySide
Static Analysis 3
HIGH 1
package.xml1
  • Declared branch 'main' does not match git branch 'latest'
LOW 2
freecad/Cubinets/File.py1
  • line 68: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
package.xml1
  • line 65: Icon file 'freecad/Cubinets/Resources/Icons/Addon.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Vytautas Rimkevicius

Lithophane

No description

96.8 / 100

Repository

https://github.com/furti/FreeCAD-Lithophane
master · Created: 2018-06-05 · Updated: 5 yr · 37 python files

Statistics

234
DL(Yr)
0
DL(Mo)
37
Stars
15
Issues
Dependencies 7
  • Compat: PySide2
  • Internal: Draft
  • Internal: Mesh
  • Internal: Points
  • Internal: PySide
  • Internal: pivy
  • Warn: bpy (Not in AddonManager allowed packages)
Static Analysis 3
HIGH 1
package.xml1
  • File not found.
LOW 2
blender/blender_processor.py2
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 100: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

lattice2 master

1.1· Tools and arrays of all sorts and kinds, and local coordinate systems

96.7 / 100

Repository

https://github.com/DeepSOIC/Lattice2
master · Created: 2015-11-26 · Updated: 3 mo · 73 python files

Statistics

13,086
DL(Yr)
1,301
DL(Mo)
84
Stars
34
Issues
Manifest
Branch
master
Version
1.1
License
LGPL-2.0-or-later
Dependencies 5
  • Internal: Draft
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Warn: Show (Not in AddonManager allowed packages)
Static Analysis 4
HIGH 1
package.xml1
  • line 8: Missing license file 'LICENSE'
LOW 3
lattice2ShapeInfoFeature.py1
  • line 155: Try, Except, Continue detected.
lattice2ValueSeriesGenerator.py1
  • line 204: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
license.*1
  • File not found.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
DeepSOIC

Motion-Control Latest

1.1.0· Link motion controller to an assembly using OPC UA.

96.6 / 100

Repository

https://github.com/Addon-Shelter/Motion-Control
Stable · v1.1.0 · Created: 2025-09-25 · Updated: 6 mo · 13 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
Latest
Version
1.1.0
License
GPL-3.0-or-later
Dependencies 3
  • Compat: PySide6
  • Pip: asyncua
  • Warn: aioconsole (Not in AddonManager allowed packages)
Static Analysis 5
HIGH 1
package.xml1
  • Declared branch 'Latest' does not match git branch 'Stable'
LOW 4
Demo/Demo_Cnc/DemoServer/opcserver.py4
  • line 147: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 147: Starting a process with a partial executable path
  • line 190: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 190: Starting a process with a partial executable path
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
PhoneDroid heissgetraenk

slic3r-tools

No description

96.3 / 100

Repository

https://github.com/limikael/freecad-slic3r-tools
master · Created: 2019-05-08 · Updated: 7 yr · 9 python files

Statistics

0
DL(Yr)
0
DL(Mo)
17
Stars
8
Issues
Dependencies 2
  • Internal: Mesh
  • Internal: PySide
Static Analysis 8
HIGH 1
package.xml1
  • File not found.
LOW 7
Slcr.py2
  • line 1: Consider possible security implications associated with the subprocess module.
  • line 39: subprocess call - check for execution of untrusted input.
SlcrDoc.py2
  • line 1: Consider possible security implications associated with the subprocess module.
  • line 109: subprocess call - check for execution of untrusted input.
build.py2
  • line 4: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 4: Starting a process with a partial executable path
license.*1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

BillOfMaterials main

1.3.3· A workbench to create Bill of Materials (BoM) independent of the assembly workbench of your choice.

96.2 / 100

Repository

https://github.com/APEbbers/BillOfMaterials-WB
Develop · Created: 2023-11-05 · Updated: 5 d · 36 python files

Statistics

0
DL(Yr)
0
DL(Mo)
34
Stars
4
Issues
Manifest
Branch
main
Version
1.3.3
License
LGPL-3.0-or-later
Dependencies 4
  • Internal: PySide
  • Pip: defusedxml
  • Pip: matplotlib
  • Pip: openpyxl
Static Analysis 9
HIGH 1
package.xml1
  • Declared branch 'main' does not match git branch 'Develop'
LOW 8
GetBOM_BIM.py2
  • line 179: Try, Except, Continue detected.
  • line 185: Try, Except, Continue detected.
Standard_Functions_BOM_WB.py5
  • line 287: Consider possible security implications associated with the subprocess module.
  • line 294: subprocess call - check for execution of untrusted input.
  • line 296: Starting a process without a shell.
  • line 300: Starting a process with a partial executable path
  • line 300: subprocess call - check for execution of untrusted input.
package.xml1
  • line 26: Icon file 'Resources/Icons/BillOfMaterialsWB.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

LCInterlocking master

1.5.1· Create interlocking parts for laser cutting or CNC milling

96 / 100

Repository

https://github.com/execuc/LCInterlocking
master · 1.5.1 · Created: 2016-06-20 · Updated: 10 mo · 32 python files

Statistics

4,560
DL(Yr)
521
DL(Mo)
197
Stars
37
Issues
Manifest
Branch
master
Version
1.5.1
License
LGPL-2.1-or-later
Dependencies 2
  • Internal: Draft
  • Internal: PySide
Static Analysis 2
HIGH 1
package.xml1
  • line 7: Element maintainer failed to validate attributes
MEDIUM 1
panel/propertieslist.py1
  • line 37: Use of possibly insecure function - consider using safer ast.literal_eval.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
execuc

Plot master

2024.11.26· Some tools to manipulate the FreeCAD plots

95.9 / 100

Repository

https://github.com/FreeCAD/Plot
2024.11.26 · 2024.11.26 · Created: 2018-09-22 · Updated: 2 yr · 16 python files

Statistics

0
DL(Yr)
0
DL(Mo)
17
Stars
0
Issues
Manifest
Branch
master
Version
2024.11.26
License
LGPL-2.1-or-later
Dependencies 4
  • Internal: PySide
  • Pip: matplotlib
  • Warn: PyQt5 (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 3
HIGH 1
package.xml1
  • Declared branch 'master' does not match git branch '2024.11.26'
MEDIUM 1
setup.py1
  • line 8: Use of exec detected.
LOW 1
package.xml1
  • line 13: Icon file 'freecad/plot/resources/icons/Plot_Icon.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Jose Luis Cercós Pita

InventorLoader master

1.5.1· This plugin enables FreeCAD to import Inventor part files (*.IPT), ACIS files (*.SAT, *.SAB), 3D-Solids from DXF files and Fusion360 (*.f3d)...

95.6 / 100

Repository

https://github.com/jmplonka/InventorLoader
master · Created: 2017-02-09 · Updated: 2 yr · 39 python files

Statistics

5,390
DL(Yr)
827
DL(Mo)
169
Stars
59
Issues
Manifest
Branch
master
Version
1.5.1
License
LGPL-3.0-or-later
Dependencies 10
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: ezdxf
  • Pip: olefile
  • Pip: xlrd
  • Pip: xlutils
  • Pip: xlwt
Static Analysis 6
HIGH 1
package.xml1
  • line 6: Missing license file 'None'
MEDIUM 1
Acis.py1
  • line 276: Use of possibly insecure function - consider using safer ast.literal_eval.
LOW 4
Acis.py1
  • line 5051: Possible hardcoded password: '('
InitGui.py2
  • line 15: subprocess call - check for execution of untrusted input.
  • line 17: Consider possible security implications associated with the subprocess module.
package.xml1
  • line 8: Icon file 'Icon.png' is not scalable (svg)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
jmplonka

Road main

2026.04.11· Road is the Transportation and Geomatics Engineering workbench for FreeCAD.

95.6 / 100

Repository

https://github.com/HakanSeven12/Road
main · Created: 2025-01-01 · Updated: 3 mo · 128 python files

Statistics

3,118
DL(Yr)
25
DL(Mo)
50
Stars
9
Issues
Manifest
Branch
main
Version
2026.04.11
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Dependencies 7
  • Internal: Mesh
  • Internal: Points
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
  • Pip: pyproj
  • Pip: scipy
Static Analysis 17
MEDIUM 3
freecad/road/tasks/task_selection.py2
  • line 40: Possible SQL injection vector through string-based query construction.
  • line 102: Possible SQL injection vector through string-based query construction.
modules/landxml/landxml_reader.py1
  • line 166: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 14
freecad/road/geometry/alignment/alignment.py2
  • line 371: Try, Except, Continue detected.
  • line 645: Try, Except, Continue detected.
freecad/road/objects/road.py1
  • line 78: Try, Except, Continue detected.
freecad/road/viewproviders/view_terrain.py3
  • line 24: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 24: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 24: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/road/viewproviders/view_volume.py3
  • line 20: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 20: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 20: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
modules/landxml/alignment_parser.py1
  • line 9: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
modules/landxml/cgpoint_parser.py1
  • line 9: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
modules/landxml/landxml_reader.py1
  • line 4: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
modules/landxml/profile_parser.py1
  • line 9: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
modules/landxml/surface_parser.py1
  • line 9: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Hakan Seven

MeshToFeatures main

0.17.6· Reverse-engineer triangle meshes (STL) of prismatic parts into editable PartDesign bodies: surface recognition, design-intent parameter snap...

95.5 / 100

Repository

https://github.com/MasoudMiM/MeshToFeatures
main · v0.17.6 · Created: 2026-07-11 · Updated: 6 d · 63 python files

Statistics

716
DL(Yr)
551
DL(Mo)
15
Stars
0
Issues
Manifest
Branch
main
Version
0.17.6
License
LGPL-2.1-or-later
Dependencies 7
  • Internal: PySide
  • Pip: Shapely
  • Pip: numpy
  • Pip: scipy
  • Pip: trimesh
  • Warn: manifold3d (Not in AddonManager allowed packages)
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 7
HIGH 1
Layout1
  • Invalid __init__.py file in freecad package root.
MEDIUM 1
freecad/meshtofeatures_wb/tests/test_real_stl.py1
  • line 31: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 5
freecad/meshtofeatures_wb/build.py2
  • line 246: Try, Except, Continue detected.
  • line 908: Try, Except, Continue detected.
freecad/meshtofeatures_wb/core/history.py1
  • line 1844: Try, Except, Continue detected.
freecad/meshtofeatures_wb/tests/test_namespace.py2
  • line 20: Consider possible security implications associated with the subprocess module.
  • line 58: subprocess call - check for execution of untrusted input.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Masoud Masoumi

btl main

0.9.9· A FreeCAD Path Addon to manage your tool library.

95.5 / 100

Repository

https://github.com/knipknap/better-tool-library
main · Created: 2023-07-15 · Updated: 1 yr · 49 python files

Statistics

292
DL(Yr)
0
DL(Mo)
43
Stars
17
Issues
Manifest
Branch
main
Version
0.9.9
License
MIT
Dependencies 7
  • Internal: PySide
  • Pip: Path
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
  • Warn: PyQt5 (Not in AddonManager allowed packages)
  • Warn: pip (Not in AddonManager allowed packages)
Static Analysis 7
HIGH 1
package.xml1
  • line 2: Expecting a namespace for element package
MEDIUM 1
btl/util.py1
  • line 21: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 5
btl/params.py1
  • line 154: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
btl/util.py1
  • line 3: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
btl/version.py3
  • line 2: Consider possible security implications associated with the subprocess module.
  • line 8: Starting a process with a partial executable path
  • line 8: subprocess call - check for execution of untrusted input.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Samuel Abels

Nesting main

2026.9.0· A workbench for 2D nesting of shapes, using no-fit-polygon (Minkowski sum) placement with a genetic algorithm optimizer. Includes a manual n...

95.3 / 100

Repository

https://github.com/StevePeters-US/Freecad-Nesting-Workbench
main · Created: 2025-10-24 · Updated: 8 d · 60 python files

Statistics

324
DL(Yr)
324
DL(Mo)
10
Stars
7
Issues
Manifest
Branch
main
Version
2026.9.0
License
LGPL-2.1-or-later, OFL-1.1
Dependencies 6
  • Internal: Draft
  • Internal: PySide
  • Internal: pivy
  • Pip: Path
  • Pip: Shapely
  • Pip: numpy
Static Analysis 20
MEDIUM 3
Resources/translations/update_translations.py2
  • line 105: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 167: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
freecad/nestingworkbench/commands/command_about.py1
  • line 27: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 17
Resources/translations/update_translations.py4
  • line 19: Consider possible security implications associated with the subprocess module.
  • line 21: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 22: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 185: subprocess call - check for execution of untrusted input.
freecad/nestingworkbench/Tools/Nesting/algorithms/base_nester.py3
  • line 132: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 160: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 180: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/nestingworkbench/Tools/Nesting/algorithms/physics_nester.py4
  • line 24: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 31: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 32: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 45: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/nestingworkbench/Tools/Nesting/ga_coordinator.py4
  • line 197: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 251: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 253: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 647: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/nestingworkbench/Tools/Nesting/ga_snapshot.py1
  • line 170: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/nestingworkbench/commands/command_about.py1
  • line 8: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Steve Peters

GearWorkBench main

1.4· Designs parametric gears for 3D printing — spur, helical, rack, bevel, and cycloidal, with circular, square, hexagonal, and DIN keyway bores...

94.9 / 100

Repository

https://github.com/iplayfast/GearWorkBench
1.4 · 1.4 · Created: 2025-12-11 · Updated: 2 d · 37 python files

Statistics

147
DL(Yr)
147
DL(Mo)
5
Stars
0
Issues
Manifest
Branch
main
Version
1.4
License
LGPL-2.1-or-later
Dependencies 3
  • Internal: PySide
  • Internal: Sketcher
  • Pip: numpy
Static Analysis 22
HIGH 1
package.xml1
  • Declared branch 'main' does not match git branch '1.4'
LOW 21
freecad/GearWorkBench/cycloidFun.py21
  • line 1042: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1042: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1042: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1047: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1047: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1047: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1052: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1052: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1052: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1057: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1057: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1057: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1062: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1062: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1062: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1067: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1067: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1067: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1072: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1072: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • … 1 more issues
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Chris Bruner

DynamicData master

2.78· Container object for holding custom properties, alternative to spreadsheet

94.9 / 100

Repository

https://github.com/mwganson/DynamicData
master · Created: 2018-09-22 · Updated: 6 mo · 4 python files

Statistics

2,858
DL(Yr)
0
DL(Mo)
51
Stars
24
Issues
Manifest
Branch
master
Version
2.78
License
LGPL-2.1-or-later
Dependencies 2
  • Internal: PySide
  • Pip: Requests
Static Analysis 4
HIGH 1
package.xml1
  • line 2: Expecting a namespace for element package
MEDIUM 2
freecad/Dynamic_Data/init_gui.py2
  • line 113: Call to requests without timeout
  • line 117: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 1
freecad/Dynamic_Data/init_gui.py1
  • line 98: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
TheMarkster

MeshStudy main

0.1.3· Automates mesh refinement studies for (FEA/FEM).

94.8 / 100

Repository

https://github.com/eng-abdalla-abbas/MeshStudy
main · v0.1.3 · Created: 2026-08-19 · Updated: 13 d · 28 python files

Statistics

0
DL(Yr)
0
DL(Mo)
4
Stars
0
Issues
Manifest
Branch
main
Version
0.1.3
License
LGPL-2.1-or-later
Dependencies 4
  • Internal: PySide
  • Internal: pivy
  • Pip: matplotlib
  • Warn: femtools (Not in AddonManager allowed packages)
Static Analysis 5
HIGH 1
package.xml1
  • line 9: Missing license file 'None'
MEDIUM 2
freecad/MeshStudy/gui/commands.py2
  • line 173: Possible SQL injection vector through string-based query construction.
  • line 175: Possible SQL injection vector through string-based query construction.
LOW 2
package.xml2
  • line 12: Icon file 'Resources/Icons/Workbench.png' is too big (>16kB)
  • line 12: Icon file 'Resources/Icons/Workbench.png' is not scalable (svg)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Abdalla Abbas

3D_Printing_Tools

No description

94.6 / 100

Repository

https://github.com/mark1791/3D_Printing_Tools
master · Created: 2019-01-30 · Updated: 7 yr · 5 python files

Statistics

7,351
DL(Yr)
924
DL(Mo)
55
Stars
7
Issues
Dependencies 2
  • Internal: Mesh
  • Internal: PySide
Static Analysis 7
HIGH 1
package.xml1
  • File not found.
MEDIUM 2
_SMutils.py2
  • line 53: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 63: Use of possibly insecure function - consider using safer ast.literal_eval.
LOW 4
SM_Graphic_Properties.py3
  • line 42: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 43: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 44: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
SM_Mesh_Solid.py1
  • line 43: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

Assembly3 master

0.12.3· Assembly3 workbench an attempt to bring assembly capability to FreeCAD using SolveSpace constraint solver

94.6 / 100

Repository

https://github.com/realthunder/FreeCAD_assembly3
master · Created: 2017-09-10 · Updated: 11 mo · 18 python files

Statistics

4,702
DL(Yr)
558
DL(Mo)
906
Stars
334
Issues
Manifest
Branch
master
Version
0.12.3
License
GPL-3.0-only
Dependencies 10
  • Compat: PySide2
  • Internal: Draft
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
  • Pip: scipy
  • Pip: sympy
  • Warn: py_slvs (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
  • Warn: slvs (Not in AddonManager allowed packages)
Static Analysis 7
HIGH 1
Layout1
  • Invalid __init__.py file in root.
MEDIUM 2
freecad/asm3/deps/six.py1
  • line 709: Use of exec detected.
setup.py1
  • line 7: Use of exec detected.
LOW 4
freecad/asm3/install_prompt.py3
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 68: subprocess call - check for execution of untrusted input.
  • line 71: subprocess call - check for execution of untrusted input.
package.xml1
  • line 12: Icon file 'freecad/asm3/Gui/Resources/icons/AssemblyWorkbench.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
RealThunder

DesignSPHysics master

0.8.2 (29-05-2026)· DesignSPHysics is a macro/addon for FreeCAD that provides a Graphical User Interface for fluid and multi-physics solver DualSPHysics

94.4 / 100

Repository

https://github.com/DualSPHysics/DesignSPHysics
master · Created: 2018-07-31 · Updated: 4 mo · 315 python files

Statistics

1,715
DL(Yr)
212
DL(Mo)
155
Stars
32
Issues
Manifest
Branch
master
Version
0.8.2 (29-05-2026)
License
GPL-3.0-or-later
Dependencies 6
  • Compat: PySide6
  • Internal: Draft
  • Internal: Fem
  • Internal: Mesh
  • Warn: defusedexpat (Not in AddonManager allowed packages)
  • Warn: ordereddict (Not in AddonManager allowed packages)
Static Analysis 20
MEDIUM 4
mod/dataobjects/configuration/executable_paths.py1
  • line 114: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
mod/main.py1
  • line 95: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
mod/tools/stdout_tools.py1
  • line 46: Probable insecure usage of temp file/directory.
mod/xml/importer.py1
  • line 144: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 16
mod/dataobjects/configuration/executable_paths.py1
  • line 9: Consider possible security implications associated with pickle module.
mod/dataobjects/motion/focused_piston_wave_gen.py1
  • line 34: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
mod/dataobjects/motion/irregular_flap_wave_gen.py1
  • line 30: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
mod/dataobjects/motion/irregular_piston_wave_gen.py1
  • line 29: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
mod/dataobjects/relaxation_zone/relaxation_zone_irregular.py1
  • line 16: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
mod/tools/file_tools.py2
  • line 16: Consider possible security implications associated with pickle module.
  • line 23: Consider possible security implications associated with UnpicklingError module.
mod/tools/pickle_tool.py1
  • line 2: Consider possible security implications associated with pickle module.
mod/tools/post_processing_tools.py3
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 73: subprocess call - check for execution of untrusted input.
  • line 378: subprocess call - check for execution of untrusted input.
mod/widgets/dock/dock_widgets/gencase_completed_dialog.py2
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 116: subprocess call - check for execution of untrusted input.
mod/xml/importer.py1
  • line 12: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
mod/xml/xmltodict.py2
  • line 9: Using XMLGenerator to parse untrusted XML data is known to be vulnerable to XML attacks. Replace XMLGenerator with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 10: Using AttributesImpl to parse untrusted XML data is known to be vulnerable to XML attacks. Replace AttributesImpl with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Iván Martínez Estévez

SimplyPrint main

1.0.0· Send your FreeCAD models, meshes and assemblies directly to the SimplyPrint cloud for slicing, storage and 3D printing. Adapts to the active...

94.4 / 100

Repository

https://github.com/SimplyPrint/freecad-integration
main · Created: 2026-06-01 · Updated: 3 mo · 17 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
main
Version
1.0.0
License
MIT
Dependencies 2
  • Internal: Mesh
  • Internal: PySide
Static Analysis 11
MEDIUM 5
build.py1
  • line 32: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
freecad/simplyprint/__init__.py1
  • line 33: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
freecad/simplyprint/api.py1
  • line 47: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
freecad/simplyprint/oauth.py2
  • line 108: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 141: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 6
build.py1
  • line 16: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/simplyprint/__init__.py1
  • line 31: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/simplyprint/state.py1
  • line 23: Possible hardcoded password: 'oauth_freecad.json'
scripts/bump_version.py3
  • line 24: Consider possible security implications associated with the subprocess module.
  • line 87: Starting a process with a partial executable path
  • line 87: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
SimplyPrint

FreeCAD-themes main

2026.08.16· Additional themes for FreeCAD

94 / 100

Repository

https://github.com/FreeCAD/FreeCAD-themes
main · Created: 2024-06-24 · Updated: 2 mo · 0 python files

Statistics

15,875
DL(Yr)
2,501
DL(Mo)
13
Stars
2
Issues
Manifest
Branch
main
Version
2026.08.16
License
LGPL-2.1-or-later
Static Analysis 2
HIGH 2
package.xml2
  • line 15: Element preferencepack has extra content: type
  • line 13: Element content has extra content: preferencepack
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
The FreeCAD Team

NordicFC main

1.0.1· Nordic themes and preference pack.

94 / 100

Repository

https://github.com/erroronline1/NordicFC
main · Created: 2025-09-20 · Updated: 5 mo · 0 python files

Statistics

2,908
DL(Yr)
515
DL(Mo)
24
Stars
2
Issues
Manifest
Branch
main
Version
1.0.1
License
LGPL-2.1-or-later
Static Analysis 2
HIGH 2
package.xml2
  • line 90: Element preferencepack has extra content: type
  • line 83: Element content has extra content: preferencepack
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
error on line 1

OpticsWorkbench main

1.3.9· Geometrical optics for FreeCAD. Performs simple raytracing through your FreeCAD objects.

94 / 100

Repository

https://github.com/chbergmann/OpticsWorkbench
main · Created: 2021-07-03 · Updated: 2 mo · 16 python files

Statistics

4,196
DL(Yr)
459
DL(Mo)
172
Stars
14
Issues
Manifest
Branch
main
Version
1.3.9
License
LGPL-2.1
Dependencies 6
  • Internal: BOPTools
  • Internal: PySide
  • Internal: Sketcher
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
Static Analysis 2
HIGH 2
package.xml2
  • line 20: Did not expect element depend there
  • line 14: Element content has extra content: workbench
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Christi

Estimate main

0.1.5· A FreeCAD workbench to estimate material quantity by volume or weight for selected parts

94 / 100

Repository

https://github.com/erroronline1/estimateWB
master · Created: 2022-03-04 · Updated: 5 mo · 6 python files

Statistics

2,312
DL(Yr)
0
DL(Mo)
15
Stars
1
Issues
Manifest
Branch
main
Version
0.1.5
License
LGPL-3.0-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 2
HIGH 2
package.xml2
  • line 44: Missing license file 'LICENSE'
  • Declared branch 'main' does not match git branch 'master'
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
error on line 1

SlopedPlanesMacro

No description

94 / 100

Repository

https://github.com/luzpaz/SlopedPlanesMacro
master · Created: 2017-11-14 · Updated: 8 yr · 14 python files

Statistics

0
DL(Yr)
0
DL(Mo)
4
Stars
0
Issues
Dependencies 2
  • Internal: PySide
  • Internal: Sketcher
Static Analysis 2
HIGH 2
package.xml1
  • File not found.
Layout1
  • Invalid __init__.py file in root.
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 0

CfdOF master

1.37.3· Computational Fluid Dynamics (CFD) based on OpenFOAM.

93.9 / 100

Repository

https://github.com/jaheyns/CfdOF
master · v1.37.3 · Created: 2016-12-02 · Updated: 4 mo · 74 python files

Statistics

23,784
DL(Yr)
2,645
DL(Mo)
722
Stars
26
Issues
Manifest
Branch
master
Version
1.37.3
License
LGPL-3.0-or-later
Dependencies 8
  • Internal: BOPTools
  • Internal: Fem
  • Internal: PySide
  • Internal: pivy
  • Pip: certifi
  • Pip: matplotlib
  • Pip: numpy
  • Warn: PyQt5 (Not in AddonManager allowed packages)
Static Analysis 25
MEDIUM 4
CfdOF/CfdPreferencePage.py1
  • line 549: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
CfdOF/CfdTools.py2
  • line 828: Probable insecure usage of temp file/directory.
  • line 1758: Use of exec detected.
CfdOF/Solve/CfdCaseWriterFoam.py1
  • line 168: Probable insecure usage of temp file/directory.
LOW 21
CfdOF/CfdPreferencePage.py1
  • line 41: Using escape to parse untrusted XML data is known to be vulnerable to XML attacks. Replace escape with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
CfdOF/CfdTools.py15
  • line 37: Consider possible security implications associated with the subprocess module.
  • line 576: subprocess call - check for execution of untrusted input.
  • line 1690: Starting a process with a partial executable path
  • line 1690: subprocess call - check for execution of untrusted input.
  • line 1692: Starting a process with a partial executable path
  • line 1692: subprocess call - check for execution of untrusted input.
  • line 1694: Starting a process with a partial executable path
  • line 1694: subprocess call - check for execution of untrusted input.
  • line 1822: Consider possible security implications associated with the subprocess module.
  • line 1827: Starting a process with a partial executable path
  • line 1827: subprocess call - check for execution of untrusted input.
  • line 1831: Starting a process with a partial executable path
  • line 1831: subprocess call - check for execution of untrusted input.
  • line 1895: subprocess call - check for execution of untrusted input.
  • line 1917: subprocess call - check for execution of untrusted input.
CfdOF/Mesh/CfdMeshTools.py3
  • line 547: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 548: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 549: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
CfdOF/WindowsRunWrapper.py2
  • line 30: Consider possible security implications associated with the subprocess module.
  • line 69: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Oliver Oxtoby

PieMenu master

1.13· The PieMenu module is a tool to accelerate and simplify your workflow in usage of FreeCAD.

93.9 / 100

Repository

https://github.com/Grubuntu/PieMenu
master · Created: 2024-01-13 · Updated: 4 mo · 7 python files

Statistics

11,628
DL(Yr)
2,312
DL(Mo)
40
Stars
0
Issues
Manifest
Branch
master
Version
1.13
License
LGPL-2.1-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 3
HIGH 2
package.xml2
  • line 7: Element maintainer failed to validate attributes
  • line 8: Missing license file 'LICENSE'
LOW 1
package.xml1
  • line 12: Icon file 'Resources/icons/PieMenu_Logo.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Grubuntu

Freecad-Built-in-themes-beta main

1.2.2· Beta versions of the preference Packs included with the FreeCAD distribution

93.9 / 100

Repository

https://github.com/MisterMakerNL/Freecad-Built-in-themes-beta
main · Created: 2023-06-11 · Updated: 2 yr · 0 python files

Statistics

2,587
DL(Yr)
177
DL(Mo)
4
Stars
1
Issues
Manifest
Branch
main
Version
1.2.2
License
LGPL-2.0-or-later
Static Analysis 3
HIGH 2
package.xml2
  • line 2: Expecting a namespace for element package
  • line 7: Missing license file '../../LICENSE'
LOW 1
package.xml1
  • line 9: Icon file 'resources/icons/Freecad-Built-in-themes-beta.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
MisterMaker

Machines Latest

1.0.0· Collection of Community Maintained Machines

93.9 / 100

Repository

https://github.com/FreeCAD/Machines
Latest · Created: 2026-03-13 · Updated: 1 mo · 0 python files

Statistics

0
DL(Yr)
0
DL(Mo)
6
Stars
4
Issues
Manifest
Branch
Latest
Version
1.0.0
License
CC-BY-SA-4.0
Static Analysis 3
HIGH 2
package.xml2
  • line 82: Did not expect element machine there
  • line 83: Element content has extra content: machine
LOW 1
package.xml1
  • line 58: Icon file 'Resources/Icons/Logo.svg' is too big (>16kB)
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Sliptonic

STEMFIE main

0.3.1· A simple workbench for generating STEMFIE system components.

93.9 / 100

Repository

https://github.com/bilbaomakers/StemfieWB
main · 0.3.1 · Created: 2021-07-06 · Updated: 2 yr · 15 python files

Statistics

0
DL(Yr)
0
DL(Mo)
25
Stars
5
Issues
Manifest
Branch
main
Version
0.3.1
License
GPL-2.0-or-later
Dependencies 2
  • Pip: numpy
  • Warn: pygears (Not in AddonManager allowed packages)
Static Analysis 3
HIGH 2
package.xml2
  • line 45: Element workbench has extra content: text
  • line 45: Element content has extra content: workbench
LOW 1
freecad/stemfie/Stemfie.py1
  • line 79: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
Bilbao Makers hasecilu

SteelColumn

No description

93.9 / 100

Repository

https://github.com/ebrahimraeyat/momen
master · Created: 2020-08-28 · Updated: 2 yr · 16 python files

Statistics

0
DL(Yr)
0
DL(Mo)
9
Stars
0
Issues
Dependencies 8
  • Compat: PySide2
  • Internal: Arch
  • Internal: Draft
  • Internal: PySide
  • Pip: ezdxf
  • Warn: GitPython (Not in AddonManager allowed packages)
  • Warn: PyQt5 (Not in AddonManager allowed packages)
  • Warn: sec (Not in AddonManager allowed packages)
Static Analysis 3
HIGH 2
package.xml1
  • File not found.
Layout1
  • Invalid __init__.py file in root. Change to Init.py
LOW 1
techdraw.py1
  • line 296: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

OpenTheme main

2026.10.03· An accessible and coordinated set of Light and Dark themes for FreeCAD

93.8 / 100

Repository

https://github.com/obelisk79/OpenTheme
main · Created: 2024-01-24 · Updated: today · 2 python files

Statistics

56,918
DL(Yr)
6,283
DL(Mo)
117
Stars
50
Issues
Manifest
Branch
main
Version
2026.10.03
License
LGPL-2.1-or-later
Static Analysis 4
HIGH 2
package.xml2
  • line 16: Element preferencepack has extra content: type
  • line 13: Element content has extra content: preferencepack
LOW 2
package.xml2
  • line 10: Icon file 'resources/icons/OpenTheme.png' is too big (>16kB)
  • line 10: Icon file 'resources/icons/OpenTheme.png' is not scalable (svg)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Obelisk79

Color-Palette-Theme main

2.4.4· Choose your colors with the "ColorPalette" Theme and increase the focus on objects and texts(FreeCAD v1.1.0 ≥)

93.8 / 100

Repository

https://github.com/altangarts/FreeCAD-Themes-ColorPalette
main · Created: 2024-12-25 · Updated: today · 7 python files

Statistics

7,820
DL(Yr)
1,243
DL(Mo)
14
Stars
1
Issues
Manifest
Branch
main
Version
2.4.4
License
LGPL-2.1-or-later
Dependencies 4
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Internal: pivy
Static Analysis 4
HIGH 2
package.xml2
  • line 20: Element preferencepack has extra content: type
  • line 12: Element content has extra content: workbench
LOW 2
overlay_panel_buttons.py1
  • line 40: Try, Except, Continue detected.
workbench_combobox.py1
  • line 165: Try, Except, Continue detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
altangarts

Alternate_OpenSCAD master

1.0.0· An alternate OpenSCAD importer with some experimental features.

93.7 / 100

Repository

https://github.com/KeithSloan/OpenSCAD_Alt_Import
master · Created: 2020-02-04 · Updated: 2 mo · 19 python files

Statistics

4,903
DL(Yr)
693
DL(Mo)
17
Stars
10
Issues
Manifest
Branch
master
Version
1.0.0
License
LGPL-2.1-or-later
Dependencies 8
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: pivy
  • Pip: ezdxf
  • Pip: numpy
  • Pip: ply
  • Warn: scadParser (Not in AddonManager allowed packages)
Static Analysis 27
MEDIUM 4
OpenSCADHull.py3
  • line 206: Probable insecure usage of temp file/directory.
  • line 207: Probable insecure usage of temp file/directory.
  • line 208: Probable insecure usage of temp file/directory.
importAltCSG.py1
  • line 981: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 23
DXFObjects.py2
  • line 134: Consider possible security implications associated with the subprocess module.
  • line 140: subprocess call - check for execution of untrusted input.
OpenSCADCommands.py3
  • line 77: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 77: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 77: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
OpenSCADObjects.py2
  • line 349: Consider possible security implications associated with the subprocess module.
  • line 355: subprocess call - check for execution of untrusted input.
OpenSCADUtils.py11
  • line 61: Consider possible security implications associated with the subprocess module.
  • line 72: Consider possible security implications associated with the subprocess module.
  • line 87: Starting a process with a partial executable path
  • line 87: subprocess call - check for execution of untrusted input.
  • line 99: Starting a process with a partial executable path
  • line 99: subprocess call - check for execution of untrusted input.
  • line 127: Consider possible security implications associated with the subprocess module.
  • line 134: subprocess call - check for execution of untrusted input.
  • line 165: Consider possible security implications associated with the subprocess module.
  • line 166: Consider possible security implications associated with the subprocess module.
  • line 170: subprocess call - check for execution of untrusted input.
importAltCSG.py4
  • line 33: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 521: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 521: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 521: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
package.xml1
  • line 72: Icon file 'freecad/OpenSCAD_Alt_Import/Resources/icons/OpenSCAD_Alternate.png' is not scalable (svg)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Keith Sloan

FreeCAD-Ribbon main

1.12.0dev· A customizable ribbon interface for FreeCAD

93.6 / 100

Repository

https://github.com/APEbbers/FreeCAD-Ribbon
Develop · Created: 2024-09-28 · Updated: 4 d · 48 python files

Statistics

0
DL(Yr)
0
DL(Mo)
140
Stars
7
Issues
Manifest
Branch
main
Version
1.12.0dev
License
GPL-3.0-or-later
Dependencies 7
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Pip: Requests
  • Pip: defusedxml
  • Pip: matplotlib
  • Pip: numpy
Static Analysis 35
HIGH 1
package.xml1
  • Declared branch 'main' does not match git branch 'Develop'
LOW 34
CacheFunctions.py3
  • line 583: Try, Except, Continue detected.
  • line 628: Try, Except, Continue detected.
  • line 676: Try, Except, Continue detected.
FCBinding.py8
  • line 25: Consider possible security implications associated with the subprocess module.
  • line 2260: Try, Except, Continue detected.
  • line 2303: Try, Except, Continue detected.
  • line 2346: Try, Except, Continue detected.
  • line 2553: Try, Except, Continue detected.
  • line 5558: Try, Except, Continue detected.
  • line 8522: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 8522: Starting a process with a partial executable path
LoadAddCommands.py4
  • line 1753: Try, Except, Continue detected.
  • line 2235: Try, Except, Continue detected.
  • line 2280: Try, Except, Continue detected.
  • line 2328: Try, Except, Continue detected.
LoadDesign_Ribbon.py5
  • line 2980: Try, Except, Continue detected.
  • line 4430: Try, Except, Continue detected.
  • line 4475: Try, Except, Continue detected.
  • line 4523: Try, Except, Continue detected.
  • line 5130: Try, Except, Continue detected.
Standard_Functions_Ribbon.py14
  • line 260: Consider possible security implications associated with the subprocess module.
  • line 268: Starting a process with a partial executable path
  • line 268: subprocess call - check for execution of untrusted input.
  • line 270: Starting a process without a shell.
  • line 274: Starting a process with a partial executable path
  • line 274: subprocess call - check for execution of untrusted input.
  • line 276: Starting a process with a partial executable path
  • line 276: subprocess call - check for execution of untrusted input.
  • line 323: Consider possible security implications associated with the subprocess module.
  • line 330: subprocess call - check for execution of untrusted input.
  • line 332: Starting a process without a shell.
  • line 336: Starting a process with a partial executable path
  • line 336: subprocess call - check for execution of untrusted input.
  • line 964: Try, Except, Continue detected.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

nurbs

No description

93.4 / 100

Repository

https://github.com/microelly2/freecad-nurbs
master · Created: 2016-08-01 · Updated: 7 yr · 110 python files

Statistics

0
DL(Yr)
0
DL(Mo)
26
Stars
6
Issues
Dependencies 8
  • Internal: Draft
  • Internal: Mesh
  • Internal: Points
  • Internal: PySide
  • Internal: pivy
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
Static Analysis 19
HIGH 1
package.xml1
  • File not found.
MEDIUM 2
nurbswb/needle_models.py1
  • line 913: Use of possibly insecure function - consider using safer ast.literal_eval.
nurbswb/sole_models.py1
  • line 99: Use of possibly insecure function - consider using safer ast.literal_eval.
LOW 16
examples/example_create_random_nurbs_with_grids.py6
  • line 27: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 28: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 31: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 37: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 38: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 42: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
nurbswb/mesh_generator.py9
  • line 110: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 110: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 110: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 137: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 137: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 137: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 153: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 153: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 153: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
license.*1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

Lapidary main

0.2.0· Design faceted gemstones: parametric facet tiers driven by index gear, angle and index list. GemCad .ASC interchange, printable 2D faceting ...

93.2 / 100

Repository

https://github.com/Dominic-Lentini/freecad-gemstone
main · Created: 2026-08-22 · Updated: 20 d · 82 python files

Statistics

0
DL(Yr)
0
DL(Mo)
1
Stars
0
Issues
Manifest
Branch
main
Version
0.2.0
License
LGPL-2.1-or-later
Dependencies 5
  • Compat: PySide6
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 12
HIGH 1
freecad/lapidary/optics/study_feature.py1
  • line 329: Use of weak SHA1 hash for security. Consider usedforsecurity=False
MEDIUM 3
tests/test_icons.py2
  • line 54: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 73: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
tests/test_packaging.py1
  • line 19: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 8
freecad/lapidary/faceting/asc_io/parser.py2
  • line 89: Possible hardcoded password: 'n'
  • line 97: Possible hardcoded password: 'G'
freecad/lapidary/faceting/taskpanels/facettier_panel.py1
  • line 1134: Try, Except, Continue detected.
tests/test_icons.py1
  • line 12: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
tests/test_packaging.py4
  • line 12: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 115: Consider possible security implications associated with the subprocess module.
  • line 117: Starting a process with a partial executable path
  • line 117: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Dominic

Design456 main

0.00.1· Direct Modeling Workbench for FreeCAD

93.1 / 100

Repository

https://github.com/MariwanJ/Design456
main · Created: 2021-01-29 · Updated: 2 d · 80 python files

Statistics

2,156
DL(Yr)
47
DL(Mo)
65
Stars
4
Issues
Manifest
Branch
main
Version
0.00.1
License
GPL-3.0-or-later
Dependencies 6
  • Internal: BOPTools
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: pivy
  • Warn: PyQt5 (Not in AddonManager allowed packages)
Static Analysis 11
HIGH 2
package.xml2
  • line 2: Expecting a namespace for element package
  • line 8: Missing license file 'LICENSE'
LOW 9
freecad/Design456/Design456Parts1.py6
  • line 466: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 467: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 468: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 469: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 470: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 471: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/Design456/FACE_D.py3
  • line 168: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 169: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 170: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Mariwan Jalal

workfeature

No description

93 / 100

Repository

https://github.com/Rentlau/WorkFeature-WB
master · Created: 2018-01-29 · Updated: 2 yr · 35 python files

Statistics

0
DL(Yr)
0
DL(Mo)
13
Stars
6
Issues
Dependencies 3
  • Internal: PySide
  • Pip: numpy
  • Warn: opencv-python (Not in AddonManager allowed packages)
Static Analysis 3
HIGH 2
package.xml1
  • File not found.
Layout1
  • Invalid __init__.py file in root. Change to Init.py
MEDIUM 1
WF_centerFacePoint.py1
  • line 192: Use of possibly insecure function - consider using safer ast.literal_eval.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

Assembly4.1 main

0.61.0-0.2· This assembly workbench use lets you put FreeCAD Part and Body together inside a standard Assembly container.

92 / 100

Repository

https://github.com/leoheck/FreeCAD_Assembly4.1
main · Created: 2025-06-23 · Updated: 4 mo · 33 python files

Statistics

11,883
DL(Yr)
1,369
DL(Mo)
23
Stars
4
Issues
Manifest
Branch
main
Version
0.61.0-0.2
License
LGPL-2.1-only
Dependencies 5
  • Internal: PySide
  • Internal: pivy
  • Pip: Pillow
  • Pip: numpy
  • Warn: opencv-python (Not in AddonManager allowed packages)
Static Analysis 6
HIGH 1
package.xml1
  • line 2: Expecting a namespace for element package
MEDIUM 5
freecad/Asm4p1/asm4_objects.py5
  • line 577: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 579: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 584: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 586: Use of exec detected.
  • line 588: Use of exec detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
leoheck

SaveAndRestore main

1.1· A simple addon to save and restore your settings

91.6 / 100

Repository

https://github.com/APEbbers/SaveAndRestore
main · Created: 2025-04-23 · Updated: 5 d · 11 python files

Statistics

10,035
DL(Yr)
1,210
DL(Mo)
11
Stars
1
Issues
Manifest
Branch
main
Version
1.1
License
MIT
Dependencies 3
  • Internal: PySide
  • Pip: matplotlib
  • Warn: GitPython (Not in AddonManager allowed packages)
Static Analysis 28
HIGH 1
Standard_Functions_SaveAndRestore.py1
  • line 963: subprocess call with shell=True identified, security issue.
MEDIUM 3
Standard_Functions_SaveAndRestore.py2
  • line 497: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 534: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
StyleMapping_SaveAndRestore.py1
  • line 101: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 24
LoadDialog_SaveAndRestore.py12
  • line 41: Consider possible security implications associated with the subprocess module.
  • line 300: subprocess call - check for execution of untrusted input.
  • line 313: Starting a process with a partial executable path
  • line 313: subprocess call - check for execution of untrusted input.
  • line 362: Starting a process with a partial executable path
  • line 362: subprocess call - check for execution of untrusted input.
  • line 461: subprocess call - check for execution of untrusted input.
  • line 467: Starting a process with a partial executable path
  • line 467: subprocess call - check for execution of untrusted input.
  • line 755: Starting a process with a partial executable path
  • line 755: subprocess call - check for execution of untrusted input.
  • line 757: Starting a process without a shell.
Standard_Functions_SaveAndRestore.py11
  • line 318: Consider possible security implications associated with the subprocess module.
  • line 325: subprocess call - check for execution of untrusted input.
  • line 327: Starting a process without a shell.
  • line 331: Starting a process with a partial executable path
  • line 331: subprocess call - check for execution of untrusted input.
  • line 490: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 524: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 946: Try, Except, Continue detected.
  • line 959: Consider possible security implications associated with the subprocess module.
  • line 967: Consider possible security implications associated with the subprocess module.
  • line 975: subprocess call - check for execution of untrusted input.
StyleMapping_SaveAndRestore.py1
  • line 61: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

FreeCAD-Ribbon main

1.11.10· A customizable ribbon interface for FreeCAD

91.5 / 100

Repository

https://github.com/APEbbers/FreeCAD-Ribbon
main · Created: 2024-09-28 · Updated: 5 d · 49 python files

Statistics

10,598
DL(Yr)
1,887
DL(Mo)
140
Stars
7
Issues
Manifest
Branch
main
Version
1.11.10
License
GPL-3.0-or-later
Dependencies 8
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Pip: Requests
  • Pip: matplotlib
  • Pip: numpy
  • Warn: GitPython (Not in AddonManager allowed packages)
  • Warn: setuptools_scm (Not in AddonManager allowed packages)
Static Analysis 40
MEDIUM 5
CacheFunctions.py1
  • line 802: Call to requests without timeout
Standard_Functions_Ribbon.py3
  • line 499: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 543: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 545: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
StyleMapping_Ribbon.py1
  • line 127: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 35
CacheFunctions.py3
  • line 583: Try, Except, Continue detected.
  • line 628: Try, Except, Continue detected.
  • line 676: Try, Except, Continue detected.
FCBinding.py5
  • line 1823: Try, Except, Continue detected.
  • line 1866: Try, Except, Continue detected.
  • line 1909: Try, Except, Continue detected.
  • line 2057: Try, Except, Continue detected.
  • line 4414: Try, Except, Continue detected.
LoadAddCommands.py4
  • line 1748: Try, Except, Continue detected.
  • line 2230: Try, Except, Continue detected.
  • line 2275: Try, Except, Continue detected.
  • line 2323: Try, Except, Continue detected.
LoadDesign_Ribbon.py5
  • line 2980: Try, Except, Continue detected.
  • line 4432: Try, Except, Continue detected.
  • line 4477: Try, Except, Continue detected.
  • line 4525: Try, Except, Continue detected.
  • line 5132: Try, Except, Continue detected.
Standard_Functions_Ribbon.py17
  • line 23: Using Element to parse untrusted XML data is known to be vulnerable to XML attacks. Replace Element with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 257: Consider possible security implications associated with the subprocess module.
  • line 265: Starting a process with a partial executable path
  • line 265: subprocess call - check for execution of untrusted input.
  • line 267: Starting a process without a shell.
  • line 271: Starting a process with a partial executable path
  • line 271: subprocess call - check for execution of untrusted input.
  • line 273: Starting a process with a partial executable path
  • line 273: subprocess call - check for execution of untrusted input.
  • line 320: Consider possible security implications associated with the subprocess module.
  • line 327: subprocess call - check for execution of untrusted input.
  • line 329: Starting a process without a shell.
  • line 333: Starting a process with a partial executable path
  • line 333: subprocess call - check for execution of untrusted input.
  • line 492: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 529: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 1004: Try, Except, Continue detected.
StyleMapping_Ribbon.py1
  • line 81: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

OSAFE master

2022.05.29· This is a workbench for FreeCAD that creates foundation model from CSI ETABS model results.

91.3 / 100

Repository

https://github.com/ebrahimraeyat/OSAFE
master · Created: 2018-11-08 · Updated: 8 mo · 83 python files

Statistics

0
DL(Yr)
0
DL(Mo)
56
Stars
3
Issues
Manifest
Branch
master
Version
2022.05.29
License
LGPL-2.1-or-later
Dependencies 14
  • Internal: Arch
  • Internal: BOPTools
  • Internal: Draft
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: ezdxf
  • Pip: matplotlib
  • Pip: numpy
  • Pip: pandas
  • Warn: GitPython (Not in AddonManager allowed packages)
  • Warn: docx (Not in AddonManager allowed packages)
  • Warn: pytest (Not in AddonManager allowed packages)
  • Warn: wmi (Not in AddonManager allowed packages)
Static Analysis 24
MEDIUM 7
check_legal.py1
  • line 109: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
osafe_funcs/osafe_funcs.py4
  • line 474: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 482: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 486: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 489: Use of possibly insecure function - consider using safer ast.literal_eval.
osafe_objects/punch.py2
  • line 672: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 673: Use of possibly insecure function - consider using safer ast.literal_eval.
LOW 17
check_legal.py3
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 31: Starting a process with a partial executable path
  • line 31: subprocess call - check for execution of untrusted input.
old_punch/foundraw/safe.py1
  • line 100: Try, Except, Continue detected.
old_punch/safe.py1
  • line 126: Try, Except, Continue detected.
osafe_funcs/osafe_funcs.py1
  • line 1836: Try, Except, Continue detected.
osafe_import_export/export.py4
  • line 118: Starting a process without a shell.
  • line 131: Starting a process without a shell.
  • line 154: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 216: Starting a process without a shell.
osafe_import_export/report.py4
  • line 13: Consider possible security implications associated with the subprocess module.
  • line 16: Starting a process with a partial executable path
  • line 16: subprocess call - check for execution of untrusted input.
  • line 343: Starting a process without a shell.
osafe_import_export/safe_read_write_f2k.py1
  • line 103: Try, Except, Continue detected.
test/osafe_import_export/test_safe_read_write_f2k.py1
  • line 76: Try, Except, Continue detected.
package.xml1
  • line 9: Icon file 'osafe_images/safe.png' is not scalable (svg)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Raeyat Roknabadi Ebrahim

Assembly4 main

0.61.1· This assembly workbench allows you to assemble various native FreeCAD parts (of type Part or Body) into a standard assembly container throug...

91 / 100

Repository

https://codeberg.org/Zolko/Assembly4
main · Updated: 3 mo · 40 python files

Statistics

23,272
DL(Yr)
2,478
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
main
Version
0.61.1
License
LGPL-2.1-only
Dependencies 5
  • Internal: PySide
  • Internal: pivy
  • Pip: Pillow
  • Pip: numpy
  • Warn: opencv-python (Not in AddonManager allowed packages)
Static Analysis 16
HIGH 1
package.xml1
  • line 2: Expecting a namespace for element package
MEDIUM 5
Code/Asm4_objects.py5
  • line 577: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 579: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 584: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 586: Use of exec detected.
  • line 588: Use of exec detected.
LOW 10
Code/checkInterference.py3
  • line 269: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 270: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 271: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
Code/checkInterference_OK.py3
  • line 269: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 270: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 271: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
Code/checkInterference_zh.py3
  • line 97: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 98: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 99: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
package.xml1
  • line 16: Missing icon file '../Resources/icons/Assembly4.svg'
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Zolko

Gridfinity master

0.12.4· This Workbench will generate several variations of parametric Gridfinity bins and baseplates that can be easily customized.

91 / 100

Repository

https://github.com/Stu142/FreeCAD-Gridfinity-Workbench
master · v0.12.4 · Created: 2024-03-18 · Updated: 7 mo · 17 python files

Statistics

14,803
DL(Yr)
1,467
DL(Mo)
533
Stars
41
Issues
Manifest
Branch
master
Version
0.12.4
License
lgpl-2.1-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 3
HIGH 3
package.xml3
  • line 2: Expecting an element maintainer, got nothing
  • line 2: Invalid sequence in interleave
  • line 2: Element package failed to validate content
INFO 2
package.xml1
  • Missing maintainers information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Stuart

QuickMeasure main

2022.10.28· Measures selected features.

91 / 100

Repository

https://github.com/DanMiel/QuickMeasure
main · Created: 2022-10-04 · Updated: 1 yr · 3 python files

Statistics

5,773
DL(Yr)
569
DL(Mo)
11
Stars
4
Issues
Manifest
Branch
main
Version
2022.10.28
License
Dependencies 3
  • Internal: Draft
  • Internal: PySide
  • Pip: numpy
Static Analysis 3
HIGH 3
package.xml3
  • line 2: Expecting an element maintainer, got nothing
  • line 2: Invalid sequence in interleave
  • line 2: Element package failed to validate content
INFO 3
package.xml2
  • Missing author information in package.xml
  • Missing maintainers information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 0

MyCustomPiping main

1.1.0· A parametric piping workbench for FreeCAD. Generates pipes, flanges, fittings, valves, and gaskets sized directly from CSV databases bas...

91 / 100

Repository

https://github.com/RamDj12049/MyCustomPiping
main · Created: 2026-07-27 · Updated: 2 mo · 48 python files

Statistics

797
DL(Yr)
382
DL(Mo)
2
Stars
0
Issues
Manifest
Branch
main
Version
1.1.0
License
LGPL-2.1-or-later
Dependencies 1
  • Internal: PySide
Static Analysis 3
HIGH 3
package.xml3
  • line 24: Element workbench has extra content: text
  • line 24: Element content has extra content: workbench
  • line 27: Element package has extra content: dependencies
INFO 3
package.xml1
  • Missing author information in package.xml
Layout2
  • Uses exec based layout
  • Uses extension based layout
Authors/Maintainers 1
RamDj12049

BulletDesigner

1.0.0· Parametric bullet design workbench with ballistic and trajectory tools.

91 / 100

Repository

https://github.com/Supermagnum/BulletDesigner
main · Created: 2026-02-20 · Updated: 5 mo · 19 python files

Statistics

0
DL(Yr)
0
DL(Mo)
5
Stars
0
Issues
Manifest
Branch
Version
1.0.0
License
MIT
Dependencies 2
  • Internal: Mesh
  • Internal: PySide
Static Analysis 3
HIGH 3
package.xml3
  • line 22: Element package has extra content: category
  • Missing repository branch information (&lt;url type="repository" branch="..."&gt;...&lt;url&gt;)
  • Declared branch '' does not match git branch 'main'
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Bullet Designer Team

Launcher Latest

0.1.0· Search for commands and run them.

91 / 100

Repository

https://github.com/Addon-Shelter/Runner
Latest · Created: 2026-03-28 · Updated: 6 mo · 7 python files

Statistics

0
DL(Yr)
0
DL(Mo)
1
Stars
0
Issues
Manifest
Branch
Latest
Version
0.1.0
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Dependencies 1
  • Compat: PySide6
Static Analysis 3
HIGH 3
package.xml3
  • line 15: Invalid attribute type for element replace
  • Extra element replace in interleave
  • line 15: Element package failed to validate content
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
PhoneDroid Triplus

Machines Latest

1.0.0· Collection of Community Maintained Machines

90.9 / 100

Repository

https://github.com/FreeCAD/Machines
Stable · v1.0.0 · Created: 2026-03-13 · Updated: 6 mo · 0 python files

Statistics

0
DL(Yr)
0
DL(Mo)
6
Stars
4
Issues
Manifest
Branch
Latest
Version
1.0.0
License
CC-BY-SA-4.0
Static Analysis 4
HIGH 3
package.xml3
  • line 82: Did not expect element Machine there
  • line 83: Element content has extra content: Machine
  • Declared branch 'Latest' does not match git branch 'Stable'
LOW 1
package.xml1
  • line 58: Icon file 'Resources/Icons/Logo.svg' is too big (>16kB)
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Sliptonic

CADExchanger

No description

90.7 / 100

Repository

https://github.com/yorikvanhavre/CADExchanger
master · Created: 2017-03-25 · Updated: 2 yr · 3 python files

Statistics

2,536
DL(Yr)
290
DL(Mo)
78
Stars
6
Issues
Dependencies 1
  • Internal: PySide
Static Analysis 6
HIGH 3
CADExchangerIO.py2
  • line 188: subprocess call with shell=True identified, security issue.
  • line 220: subprocess call with shell=True identified, security issue.
package.xml1
  • File not found.
LOW 3
CADExchangerIO.py3
  • line 31: Consider possible security implications associated with the subprocess module.
  • line 74: subprocess call - check for execution of untrusted input.
  • line 99: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

pyrate

No description

90.4 / 100

Repository

https://salsa.debian.org/mess42/pyrate
master · Updated: 2 yr · 123 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Dependencies 10
  • Internal: Points
  • Internal: PySide
  • Pip: PyYAML
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
  • Pip: sympy
  • Warn: hypothesis (Not in AddonManager allowed packages)
  • Warn: nltk (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 11
HIGH 2
package.xml1
  • File not found.
Layout1
  • Invalid __init__.py file in freecad package root.
MEDIUM 3
demos/demo_loadsave.py1
  • line 269: Use of possibly insecure function - consider using safer ast.literal_eval.
pyrateoptics/core/functionobject.py1
  • line 119: Use of exec detected.
pyrateoptics/core/serializer.py1
  • line 457: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
LOW 6
pyrateoptics/core/log.py2
  • line 114: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 115: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
pyrateoptics/core/names/nltk_list_generator.py1
  • line 82: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
pyrateoptics/raytracer/localcoordinates.py3
  • line 487: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 488: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 489: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 0

Render master

2024.12.15· (UNMAINTAINED) A workbench to produce high-quality rendered images from your FreeCAD document, using open-source external rendering engines....

90.3 / 100

Repository

https://github.com/FreeCAD/FreeCAD-render
master · Created: 2017-12-17 · Updated: 5 mo · 53 python files

Statistics

15,339
DL(Yr)
1,897
DL(Mo)
237
Stars
21
Issues
Manifest
Branch
master
Version
2024.12.15
License
LGPL-2.1-or-later
Dependencies 9
  • Internal: Mesh
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
  • Pip: qtpy
  • Warn: MaterialX (Not in AddonManager allowed packages)
  • Warn: PyQt6 (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer.egg (Not in AddonManager allowed packages)
Static Analysis 23
HIGH 1
Render/plugins/materialx/importer/converter/materialx_baker.py1
  • line 497: Use of weak SHA1 hash for security. Consider usedforsecurity=False
MEDIUM 5
Render/renderers/Appleseed.py2
  • line 1439: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 1484: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Render/renderers/Cycles.py1
  • line 1025: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Render/virtualenv.py2
  • line 386: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 418: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 17
Render/plugins/materialx/importer/materialx_importer.py2
  • line 25: Consider possible security implications associated with the subprocess module.
  • line 77: subprocess call - check for execution of untrusted input.
Render/prefpage.py2
  • line 32: Consider possible security implications associated with the subprocess module.
  • line 305: subprocess call - check for execution of untrusted input.
Render/rdrexecutor.py2
  • line 34: Consider possible security implications associated with the subprocess module.
  • line 94: subprocess call - check for execution of untrusted input.
Render/renderers/Appleseed.py2
  • line 48: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 49: Using xml.dom.minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Render/renderers/Cycles.py1
  • line 74: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Render/virtualenv.py8
  • line 47: Consider possible security implications associated with the subprocess module.
  • line 240: subprocess call - check for execution of untrusted input.
  • line 275: subprocess call - check for execution of untrusted input.
  • line 299: subprocess call - check for execution of untrusted input.
  • line 367: subprocess call - check for execution of untrusted input.
  • line 396: subprocess call - check for execution of untrusted input.
  • line 420: subprocess call - check for execution of untrusted input.
  • line 520: subprocess call - check for execution of untrusted input.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 3
Yorik Van Havre No current maintainer howetuft

woodworking master

3.3.20260801· Woodworking workbench was designed primarily for creating simple cabinets for your home or garage. However, it includes many features that w...

90.2 / 100

Repository

https://github.com/dprojects/Woodworking
master · Created: 2022-02-25 · Updated: 2 mo · 159 python files

Statistics

29,866
DL(Yr)
2,748
DL(Mo)
570
Stars
0
Issues
Manifest
Branch
master
Version
3.3.20260801
License
MIT
Dependencies 9
  • Internal: BOPTools
  • Internal: Draft
  • Internal: PySide
  • Internal: Sketcher
  • Internal: Spreadsheet
  • Internal: TechDraw
  • Internal: pivy
  • Pip: Path
  • Warn: deep_translator (Not in AddonManager allowed packages)
Static Analysis 26
MEDIUM 8
Tools/debugInfo.py2
  • line 241: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 858: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
Tools/scanObjects.py1
  • line 1330: Use of possibly insecure function - consider using safer ast.literal_eval.
Tools/setTextures.py1
  • line 517: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
Tools/sheet2export.py1
  • line 877: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
loadMenu.py2
  • line 217: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 285: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
translations/make_AI_translation.py1
  • line 167: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 18
Tools/MagicPanels.py4
  • line 2451: Try, Except, Continue detected.
  • line 2572: Try, Except, Continue detected.
  • line 3224: Try, Except, Continue detected.
  • line 4029: Try, Except, Continue detected.
Tools/align2Curve.py1
  • line 138: Try, Except, Continue detected.
Tools/debugInfo.py1
  • line 1015: Try, Except, Continue detected.
Tools/magicView.py2
  • line 350: Try, Except, Continue detected.
  • line 421: Try, Except, Continue detected.
Tools/makeBeautiful.py1
  • line 32: Try, Except, Continue detected.
Tools/selected2Outside.py1
  • line 27: Try, Except, Continue detected.
Tools/sheet2export.py2
  • line 875: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 886: Try, Except, Continue detected.
Tools/showConstraints.py1
  • line 23: Try, Except, Continue detected.
Tools/showPlacement.py1
  • line 27: Try, Except, Continue detected.
Tools/showVertex.py1
  • line 35: Try, Except, Continue detected.
translations/make_AI_translation.py1
  • line 1: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
package.xml2
  • line 24: Icon file 'Icons/Woodworking.png' is too big (>16kB)
  • line 24: Icon file 'Icons/Woodworking.png' is not scalable (svg)
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Darek L

EasyProfileFrame main

0.0.1· Simplifies the creation of frames using profiles, such as aluminum profiles. It also includes support for exporting Bill of Materials (BOM).

89.9 / 100

Repository

https://github.com/ovo-Tim/EasyProfileFrame
main · Created: 2025-01-19 · Updated: 1 yr · 10 python files

Statistics

5,293
DL(Yr)
645
DL(Mo)
29
Stars
7
Issues
Manifest
Branch
main
Version
0.0.1
License
LGPL-3.0-or-later
Dependencies 3
  • Internal: PySide
  • Internal: Sketcher
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 5
HIGH 3
package.xml3
  • line 2: Expecting an element maintainer, got nothing
  • line 2: Invalid sequence in interleave
  • line 2: Element package failed to validate content
MEDIUM 1
setup.py1
  • line 11: Use of exec detected.
LOW 1
package.xml1
  • line 20: Icon file 'freecad/easy_profile_frame/resources/icons/MakerWorkbench_Aluproft_Cmd.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing maintainers information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
ovo-Tim

Smooth-Toolsync master

0.7.0· Synchronize FreeCAD's CAM tool libraries with a Loobric tool data server. Adds "Loobric" to the CAM workbench toolbar (a modeless Sync / Ma...

89.9 / 100

Repository

https://github.com/loobric/smooth-freecad.git
master · Created: 2025-10-27 · Updated: 2 mo · 37 python files

Statistics

0
DL(Yr)
0
DL(Mo)
5
Stars
1
Issues
Manifest
Branch
master
Version
0.7.0
License
MIT
Dependencies 4
  • Internal: PySide
  • Pip: Path
  • Warn: argcomplete (Not in AddonManager allowed packages)
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 5
HIGH 3
freecad/Loobric/mirrorsync.py1
  • line 84: Use of weak SHA1 hash for security. Consider usedforsecurity=False
package.xml1
  • line 39: Element package has extra content: tags
Layout1
  • Invalid __init__.py file in freecad package root.
MEDIUM 1
freecad/Loobric/jobset.py1
  • line 276: Possible SQL injection vector through string-based query construction.
LOW 1
freecad/Loobric/sync.py1
  • line 663: Try, Except, Continue detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Brad Collette

MBDWorkbench main

0.1.0· Model-Based Definition workbench for semantic PMI authoring, validation, AP242 STEP export, and first-pass AP242 semantic PMI import.

89.7 / 100

Repository

https://github.com/ChipsWoodShop/FreeCAD-MBDWorkbench
main · Created: 2026-05-16 · Updated: 2 mo · 32 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
1
Issues
Manifest
Branch
main
Version
0.1.0
License
LGPL-2.1-only
Dependencies 4
  • Internal: Draft
  • Internal: PySide
  • Internal: pivy
  • Warn: OCC (Not in AddonManager allowed packages)
Static Analysis 22
MEDIUM 9
tests/check_model_face_resolution.py1
  • line 120: Probable insecure usage of temp file/directory.
tests/freecad_imported_fcf_export_smoke.py1
  • line 101: Probable insecure usage of temp file/directory.
tests/headless_freecad_smoke.py3
  • line 1308: Probable insecure usage of temp file/directory.
  • line 2035: Probable insecure usage of temp file/directory.
  • line 4004: Probable insecure usage of temp file/directory.
tests/run_headless_smoke.py3
  • line 13: Probable insecure usage of temp file/directory.
  • line 15: Probable insecure usage of temp file/directory.
  • line 160: Probable insecure usage of temp file/directory.
tests/validate_package_metadata.py1
  • line 34: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 13
freecad/mbd_workbench/MBDCommands.py2
  • line 508: Try, Except, Continue detected.
  • line 5012: Try, Except, Continue detected.
freecad/mbd_workbench/MBDDimension.py3
  • line 907: Try, Except, Continue detected.
  • line 949: Try, Except, Continue detected.
  • line 979: Try, Except, Continue detected.
freecad/mbd_workbench/MBDExporter.py1
  • line 347: Try, Except, Continue detected.
freecad/mbd_workbench/MBDImporter.py1
  • line 1986: Try, Except, Continue detected.
freecad/mbd_workbench/MBDViewProvider.py1
  • line 534: Try, Except, Continue detected.
tests/run_headless_smoke.py2
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 93: subprocess call - check for execution of untrusted input.
tests/run_reference_checks.py2
  • line 3: Consider possible security implications associated with the subprocess module.
  • line 19: subprocess call - check for execution of untrusted input.
tests/validate_package_metadata.py1
  • line 7: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 3
package.xml1
  • Missing author information in package.xml
Layout2
  • Uses exec based layout
  • Uses extension based layout
Authors/Maintainers 1
Chip

osh-autodoc-workbench main

0.2.3· A workbench that support the creation of assembly manuals of open source hardware.

89 / 100

Repository

https://codeberg.org/osh-autodoc/osh-autodoc-workbench
main · Updated: 8 mo · 23 python files

Statistics

0
DL(Yr)
0
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
main
Version
0.2.3
License
LGPL-3.0-or-later
Dependencies 6
  • Compat: PySide6
  • Internal: Draft
  • Internal: PySide
  • Internal: TechDraw
  • Internal: pivy
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 9
HIGH 1
package.xml1
  • line 19: Missing license file 'None'
MEDIUM 8
freecad/OSHAutoDocWorkbench/layer_state_manager.py6
  • line 663: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 665: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 667: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 669: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 673: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 675: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/OSHAutoDocWorkbench/util/util.py1
  • line 50: Use of possibly insecure function - consider using safer ast.literal_eval.
setup.py1
  • line 13: Use of exec detected.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
J.C. Mariscal-Melgar Pieter Hijma

SaveAndRestore main

1.1.1· A simple addon to save and restore your settings

88.6 / 100

Repository

https://github.com/APEbbers/SaveAndRestore
Develop · Created: 2025-04-23 · Updated: 4 d · 11 python files

Statistics

0
DL(Yr)
0
DL(Mo)
11
Stars
1
Issues
Manifest
Branch
main
Version
1.1.1
License
MIT
Dependencies 3
  • Internal: PySide
  • Pip: matplotlib
  • Warn: GitPython (Not in AddonManager allowed packages)
Static Analysis 29
HIGH 2
Standard_Functions_SaveAndRestore.py1
  • line 963: subprocess call with shell=True identified, security issue.
package.xml1
  • Declared branch 'main' does not match git branch 'Develop'
MEDIUM 3
Standard_Functions_SaveAndRestore.py2
  • line 497: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 534: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
StyleMapping_SaveAndRestore.py1
  • line 101: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 24
LoadDialog_SaveAndRestore.py12
  • line 41: Consider possible security implications associated with the subprocess module.
  • line 333: subprocess call - check for execution of untrusted input.
  • line 346: Starting a process with a partial executable path
  • line 346: subprocess call - check for execution of untrusted input.
  • line 395: Starting a process with a partial executable path
  • line 395: subprocess call - check for execution of untrusted input.
  • line 494: subprocess call - check for execution of untrusted input.
  • line 500: Starting a process with a partial executable path
  • line 500: subprocess call - check for execution of untrusted input.
  • line 793: Starting a process with a partial executable path
  • line 793: subprocess call - check for execution of untrusted input.
  • line 795: Starting a process without a shell.
Standard_Functions_SaveAndRestore.py11
  • line 318: Consider possible security implications associated with the subprocess module.
  • line 325: subprocess call - check for execution of untrusted input.
  • line 327: Starting a process without a shell.
  • line 331: Starting a process with a partial executable path
  • line 331: subprocess call - check for execution of untrusted input.
  • line 490: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 524: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 946: Try, Except, Continue detected.
  • line 959: Consider possible security implications associated with the subprocess module.
  • line 967: Consider possible security implications associated with the subprocess module.
  • line 975: subprocess call - check for execution of untrusted input.
StyleMapping_SaveAndRestore.py1
  • line 61: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

KiConnect release

1.0.1· PCB Syncronization with KiCAD v9+

88.4 / 100

Repository

https://codeberg.org/kiconnect/KiConnect
release · v1.0.1 · Updated: 2 mo · 30 python files

Statistics

196
DL(Yr)
30
DL(Mo)
0
Stars
0
Issues
Manifest
Branch
release
Version
1.0.1
License
LGPL-2.1-or-later
Dependencies 5
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Warn: Materials (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 17
MEDIUM 11
freecad/kiconnect/api.py1
  • line 22: Probable insecure usage of temp file/directory.
freecad/kiconnect/commands/cmd_launch_pcbnew.py1
  • line 9: Probable insecure usage of temp file/directory.
freecad/kiconnect/tests/common.py2
  • line 11: Probable insecure usage of temp file/directory.
  • line 32: Probable insecure usage of temp file/directory.
freecad/kiconnect/tests/test_arc_geo.py1
  • line 39: Probable insecure usage of temp file/directory.
freecad/kiconnect/tests/test_parts.py2
  • line 26: Probable insecure usage of temp file/directory.
  • line 27: Probable insecure usage of temp file/directory.
freecad/kiconnect/tests/test_sync.py3
  • line 27: Probable insecure usage of temp file/directory.
  • line 28: Probable insecure usage of temp file/directory.
  • line 132: Probable insecure usage of temp file/directory.
setup.py1
  • line 6: Use of exec detected.
LOW 6
freecad/kiconnect/commands/cmd_launch_pcbnew.py2
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 24: subprocess call - check for execution of untrusted input.
freecad/kiconnect/tests/common.py2
  • line 3: Consider possible security implications associated with the subprocess module.
  • line 52: subprocess call - check for execution of untrusted input.
freecad/kiconnect/tests/test_api_connection.py1
  • line 3: Consider possible security implications associated with the subprocess module.
freecad/kiconnect/tests/test_arc_geo.py1
  • line 2: Consider possible security implications associated with the subprocess module.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
morgan

TitleBlock main

0.5.2.2· An extension for the TechDraw workbench to fill a TitleBlock with the aid of the Spreadsheet workbench.

88.3 / 100

Repository

https://github.com/APEbbers/TitleBlock-WB
main · Created: 2023-10-07 · Updated: 1 yr · 18 python files

Statistics

0
DL(Yr)
0
DL(Mo)
5
Stars
2
Issues
Manifest
Branch
main
Version
0.5.2.2
License
LGPL-2.1-or-later
Dependencies 4
  • Internal: PySide
  • Pip: matplotlib
  • Pip: openpyxl
  • Warn: pycurl (Not in AddonManager allowed packages)
Static Analysis 12
HIGH 3
utils/updateTranslations.py3
  • line 137: Starting a process with a shell, possible injection detected, security issue.
  • line 179: Starting a process with a shell, possible injection detected, security issue.
  • line 200: Starting a process with a shell, possible injection detected, security issue.
MEDIUM 2
utils/updateTranslations.py2
  • line 194: Using xml.sax.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 218: Using xml.sax.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 7
Standard_Functions_TB.py5
  • line 316: Consider possible security implications associated with the subprocess module.
  • line 323: subprocess call - check for execution of untrusted input.
  • line 325: Starting a process without a shell.
  • line 329: Starting a process with a partial executable path
  • line 329: subprocess call - check for execution of untrusted input.
utils/updateTranslations.py1
  • line 55: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
package.xml1
  • line 24: Icon file 'Resources/Icons/TitleBlockWB.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

Launcher Latest

0.1.0· Search for commands and run them.

88 / 100

Repository

https://github.com/Addon-Shelter/Runner
Stable · v0.1.0 · Created: 2026-03-28 · Updated: 6 mo · 2 python files

Statistics

0
DL(Yr)
0
DL(Mo)
1
Stars
0
Issues
Manifest
Branch
Latest
Version
0.1.0
License
LGPL-2.1-or-later, CC-BY-SA-4.0
Dependencies 1
  • Compat: PySide6
Static Analysis 4
HIGH 4
package.xml4
  • line 15: Invalid attribute type for element replace
  • Extra element replace in interleave
  • line 15: Element package failed to validate content
  • Declared branch 'Latest' does not match git branch 'Stable'
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 2
PhoneDroid Triplus

SearchBar main

1.8.0· Adds a search bar widget for tools, document objects, and preferences

87.6 / 100

Repository

https://github.com/APEbbers/SearchBar
Develop · Created: 2024-11-07 · Updated: 12 mo · 28 python files

Statistics

0
DL(Yr)
0
DL(Mo)
6
Stars
9
Issues
Manifest
Branch
main
Version
1.8.0
License
CCOv1
Dependencies 4
  • Internal: PySide
  • Internal: pivy
  • Pip: lxml
  • Warn: GitPython (Not in AddonManager allowed packages)
Static Analysis 10
HIGH 3
package.xml2
  • line 12: Element maintainer failed to validate attributes
  • Declared branch 'main' does not match git branch 'Develop'
Layout1
  • Invalid __init__.py file in root. Change to Init.py
MEDIUM 3
StandardFunctions_SearchBar.py2
  • line 11: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 52: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
StyleMapping_SearchBar.py1
  • line 83: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 4
ResultsToolbar.py1
  • line 117: Try, Except, Continue detected.
StandardFunctions_SearchBar.py2
  • line 4: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 39: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
StyleMapping_SearchBar.py1
  • line 43: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Paul Ebbers

kicadStepUpMod master

11.09.6· A bidirectional ECAD/MCAD collaboration between KiCAD and FreeCAD.

85.9 / 100

Repository

https://github.com/easyw/kicadStepUpMod
master · Created: 2017-09-12 · Updated: 29 d · 34 python files

Statistics

20,740
DL(Yr)
3,194
DL(Mo)
690
Stars
42
Issues
Manifest
Branch
master
Version
11.09.6
License
AGPLv3.0
Dependencies 18
  • Internal: BOPTools
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: Sketcher
  • Internal: TechDraw
  • Internal: pivy
  • Pip: Path
  • Pip: Requests
  • Pip: ezdxf
  • Pip: numpy
  • Warn: Aligner (Not in AddonManager allowed packages)
  • Warn: Caliper (Not in AddonManager allowed packages)
  • Warn: Mover (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer.egg (Not in AddonManager allowed packages)
  • Warn: stepZ (Not in AddonManager allowed packages)
  • Warn: zstd (Not in AddonManager allowed packages)
Static Analysis 18
HIGH 3
kicadStepUpCMD.py2
  • line 4683: Starting a process with a shell, possible injection detected, security issue.
  • line 4686: subprocess call with shell=True identified, security issue.
package.xml1
  • line 7: Missing license file 'LICENSE'
MEDIUM 4
InitGui.py1
  • line 433: Possible SQL injection vector through string-based query construction.
commits_num.py3
  • line 11: Call to requests without timeout
  • line 22: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 52: Call to requests without timeout
LOW 11
fps.py2
  • line 195: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 216: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
kicadStepUpCMD.py5
  • line 4670: Consider possible security implications associated with the subprocess module.
  • line 4677: Starting a process with a partial executable path
  • line 4677: subprocess call - check for execution of untrusted input.
  • line 4679: Starting a process with a partial executable path
  • line 4679: subprocess call - check for execution of untrusted input.
kicad_parser.py1
  • line 1294: Try, Except, Continue detected.
tracks.py2
  • line 206: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 236: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
license.*1
  • File not found.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Maui

fcVM main

2024.9.5· Finite element collapse analysis based on the von Mises plasticity model for use with FreeCAD

85.9 / 100

Repository

https://github.com/HarryvL/fcVM-workbench
main · Created: 2024-01-17 · Updated: 1 yr · 4 python files

Statistics

0
DL(Yr)
0
DL(Mo)
11
Stars
3
Issues
Manifest
Branch
main
Version
2024.9.5
License
Dependencies 9
  • Internal: PySide
  • Pip: matplotlib
  • Pip: numba
  • Pip: numpy
  • Pip: pyvista
  • Pip: scipy
  • Warn: cholespy (Not in AddonManager allowed packages)
  • Warn: femtools (Not in AddonManager allowed packages)
  • Warn: sksparse_minimal (Not in AddonManager allowed packages)
Static Analysis 7
HIGH 4
package.xml4
  • line 2: Expecting an element maintainer, got nothing
  • line 2: Expecting an element license, got nothing
  • line 2: Invalid sequence in interleave
  • line 2: Element package failed to validate content
MEDIUM 2
InitGui.py2
  • line 233: Use of exec detected.
  • line 280: Use of exec detected.
LOW 1
license.*1
  • File not found.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
HarryvL

FreeGrid main

2.2.0· A simple tools workbench for generating FreeGrid storage system components.

85.4 / 100

Repository

https://github.com/instancezero/in3dca-freegrid.git
main · Created: 2022-07-25 · Updated: 2 yr · 9 python files

Statistics

1,209
DL(Yr)
0
DL(Mo)
51
Stars
2
Issues
Manifest
Branch
main
Version
2.2.0
License
AGPL-3.0-or-later
Dependencies 3
  • Internal: PySide
  • Internal: Sketcher
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 12
HIGH 4
package.xml4
  • line 12: Element maintainer failed to validate attributes
  • line 14: Element maintainer failed to validate attributes
  • Extra element maintainer in interleave
  • line 14: Element package failed to validate content
MEDIUM 2
freecad/freegrid/resources/translations/update_crowdin.py2
  • line 173: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 254: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 6
freecad/freegrid/commands.py1
  • line 141: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/freegrid/resources/translations/update_crowdin.py4
  • line 75: Consider possible security implications associated with the subprocess module.
  • line 408: subprocess call - check for execution of untrusted input.
  • line 409: subprocess call - check for execution of untrusted input.
  • line 413: subprocess call - check for execution of untrusted input.
package.xml1
  • line 42: Icon file 'freecad/freegrid/resources/icons/FreeGrid.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 3
Michael K Johnson Alan Langford hasecilu

freecad_streamdeck_addon main

0.1.7· FreeCAD addon to use an Elgato Stream Deck macropad as an input device.

85 / 100

Repository

https://github.com/Giraut/freecad_streamdeck_addon
main · Created: 2024-02-25 · Updated: 3 yr · 6 python files

Statistics

0
DL(Yr)
0
DL(Mo)
21
Stars
8
Issues
Manifest
Branch
main
Version
0.1.7
License
GPL-3.0-or-later
Dependencies 3
  • Internal: PySide
  • Pip: Pillow
  • Pip: StreamDeck
Static Analysis 5
HIGH 5
streamdeck_addon.py2
  • line 102: Starting a process with a shell, possible injection detected, security issue.
  • line 493: Starting a process with a shell, possible injection detected, security issue.
package.xml3
  • line 2: Expecting an element maintainer, got nothing
  • line 2: Invalid sequence in interleave
  • line 2: Element package failed to validate content
INFO 2
package.xml1
  • Missing maintainers information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Giraut

FEMbyGEN master

2.5.5· Parametric Finite Element Analysis(FEM)

84.9 / 100

Repository

https://github.com/Serince/FEMbyGEN
master · Created: 2022-07-27 · Updated: 5 mo · 28 python files

Statistics

3,396
DL(Yr)
360
DL(Mo)
51
Stars
7
Issues
Manifest
Branch
master
Version
2.5.5
License
LGPL-2.1-only
Dependencies 11
  • Compat: PySide2
  • Compat: PySide6
  • Internal: Fem
  • Internal: Mesh
  • Internal: PySide
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
  • Warn: femtools (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer (Not in AddonManager allowed packages)
  • Warn: freecad_addon_analyzer.egg (Not in AddonManager allowed packages)
Static Analysis 12
HIGH 2
package.xml2
  • line 20: Did not expect element depend there
  • line 11: Element content has extra content: workbench
MEDIUM 9
fembygen/design/pydoe2/build_regression_matrix.py2
  • line 88: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 93: Use of possibly insecure function - consider using safer ast.literal_eval.
fembygen/topology/beso_lib.py6
  • line 701: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 871: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 979: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1040: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1077: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1125: Use of possibly insecure function - consider using safer ast.literal_eval.
fembygen/topology/beso_main.py1
  • line 442: Function call with shell=True parameter identified, possible security issue.
LOW 1
fembygen/topology/beso_main.py1
  • line 9: Consider possible security implications associated with the subprocess module.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Serdar T. Ince

drawing_dimensioning

No description

84.5 / 100

Repository

https://github.com/Addon-Shelter/Drawing-Dimensioning
v0.19.4 · 0.19.4 · Created: 2025-11-03 · Updated: 11 mo · 59 python files

Statistics

0
DL(Yr)
0
DL(Mo)
1
Stars
0
Issues
Dependencies 4
  • Internal: PySide
  • Pip: matplotlib
  • Pip: numpy
  • Warn: dxfwrite (Not in AddonManager allowed packages)
Static Analysis 14
HIGH 3
Gui/Resources/compile_resources_pack.py1
  • line 20: Starting a process with a shell, possible injection detected, security issue.
drawingDimensioning/unfold/export_to_dxf.py1
  • line 36: subprocess call with shell=True identified, security issue.
package.xml1
  • File not found.
MEDIUM 6
drawingDimensioning/proxies.py2
  • line 36: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 37: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
test/test_linear_dimension.py4
  • line 11: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 22: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 28: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 34: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 5
drawingDimensioning/proxies.py1
  • line 1: Consider possible security implications associated with pickle module.
drawingDimensioning/selectionOverlay/__init__.py1
  • line 10: Consider possible security implications associated with pickle module.
drawingDimensioning/unfold/export_to_dxf.py1
  • line 4: Consider possible security implications associated with the subprocess module.
test/test_linear_dimension.py2
  • line 8: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 10: Using xml.dom.minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

Manipulator master

1.6.4· A handy way to Move and Align objects in FreeCAD.

83.6 / 100

Repository

https://github.com/easyw/Manipulator
master · Created: 2017-10-02 · Updated: 6 mo · 10 python files

Statistics

14,250
DL(Yr)
1,533
DL(Mo)
76
Stars
24
Issues
Manifest
Branch
master
Version
1.6.4
License
GPLv3.0
Dependencies 9
  • Internal: Arch
  • Internal: Draft
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: Requests
  • Pip: numpy
  • Warn: Drawing (Not in AddonManager allowed packages)
  • Warn: Show (Not in AddonManager allowed packages)
Static Analysis 14
HIGH 3
ManipulatorCMD.py2
  • line 182: Starting a process with a shell, possible injection detected, security issue.
  • line 185: subprocess call with shell=True identified, security issue.
package.xml1
  • line 7: Missing license file 'LICENSE'
MEDIUM 7
Aligner.py1
  • line 1706: Possible SQL injection vector through string-based query construction.
InitGui.py1
  • line 144: Possible SQL injection vector through string-based query construction.
commits_num_.py3
  • line 11: Call to requests without timeout
  • line 22: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 52: Call to requests without timeout
oDraft.py2
  • line 3402: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 3643: Use of possibly insecure function - consider using safer ast.literal_eval.
LOW 4
ManipulatorCMD.py3
  • line 175: Consider possible security implications associated with the subprocess module.
  • line 178: Starting a process with a partial executable path
  • line 178: subprocess call - check for execution of untrusted input.
license.*1
  • File not found.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Maui

Part-o-magic master

1.1.0· Experiment on FreeCAD-wide automation of Part container management

83.5 / 100

Repository

https://github.com/DeepSOIC/Part-o-magic
master · Created: 2016-05-20 · Updated: 5 mo · 62 python files

Statistics

44
DL(Yr)
0
DL(Mo)
15
Stars
28
Issues
Manifest
Branch
master
Version
1.1.0
License
LGPL-2.0-or-later
Dependencies 4
  • Internal: BOPTools
  • Internal: PySide
  • Internal: pivy
  • Warn: Show (Not in AddonManager allowed packages)
Static Analysis 21
MEDIUM 16
PartOMagic/Base/FilePlant/FCObject.py1
  • line 99: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
PartOMagic/Base/FilePlant/FCProject.py9
  • line 73: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 78: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 97: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 99: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 128: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 133: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 141: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 144: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 153: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
PartOMagic/Base/FilePlant/FCProperty.py4
  • line 19: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 171: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 220: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 269: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
PartOMagic/Base/FilePlant/PropertyExpressionEngine.py2
  • line 81: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 113: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 5
PartOMagic/Base/FilePlant/FCObject.py1
  • line 2: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
PartOMagic/Base/FilePlant/FCProject.py1
  • line 2: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
PartOMagic/Base/FilePlant/FCProperty.py1
  • line 1: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
PartOMagic/Base/FilePlant/PropertyExpressionEngine.py1
  • line 1: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
PartOMagic/Gui/Tools/SelectionTools.py1
  • line 120: Try, Except, Continue detected.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
DeepSOIC

A2plus master

0.4.68· Another assembly workbench for FreeCAD, following and extending Hamish's Assembly 2 workbench hence Assembly2plus. The main goal of A2plus i...

83 / 100

Repository

https://github.com/kbwbe/A2plus
master · Created: 2018-06-28 · Updated: 8 mo · 38 python files

Statistics

27,910
DL(Yr)
3,520
DL(Mo)
206
Stars
49
Issues
Manifest
Branch
master
Version
0.4.68
License
LGPL-2.1-or-later
Dependencies 6
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Internal: Spreadsheet
  • Internal: pivy
  • Pip: numpy
Static Analysis 45
HIGH 4
CD_ConstraintViewer.py1
  • line 258: subprocess call with shell=True identified, security issue.
GuiA2p/Resources/compile_resources_pack.py1
  • line 20: Starting a process with a shell, possible injection detected, security issue.
compileA2pResources.py1
  • line 57: Starting a process with a shell, possible injection detected, security issue.
Layout1
  • Invalid __init__.py file in root. Change to Init.py
MEDIUM 1
a2p_fcdocumentreader.py1
  • line 228: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 40
CD_ConstraintViewer.py2
  • line 27: Consider possible security implications associated with the subprocess module.
  • line 298: Try, Except, Continue detected.
a2p_dependencies.py12
  • line 431: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 432: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 433: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 665: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 666: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 667: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 807: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 808: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 809: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 847: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 848: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 849: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
a2p_fcdocumentreader.py2
  • line 28: Using xml.etree.cElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.cElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 30: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
a2p_simpleXMLreader.py1
  • line 36: Using xml.sax.saxutils to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.saxutils with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
compileA2pResources.py4
  • line 66: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 66: Starting a process with a partial executable path
  • line 70: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 70: Starting a process with a partial executable path
translations/update_ts.py19
  • line 29: Consider possible security implications associated with the subprocess module.
  • line 40: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 40: Starting a process with a partial executable path
  • line 43: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 43: Starting a process with a partial executable path
  • line 50: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 50: Starting a process with a partial executable path
  • line 53: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 53: Starting a process with a partial executable path
  • line 59: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 59: Starting a process with a partial executable path
  • line 61: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 61: Starting a process with a partial executable path
  • line 73: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 73: Starting a process with a partial executable path
  • line 84: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 84: Starting a process with a partial executable path
  • line 91: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 91: Starting a process with a partial executable path
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
kbwbe

FEM_FrontISTR master

0.2.0· A FreeCAD addon that enables a parallel nonliner FEM solver FrontISTR.

82.9 / 100

Repository

https://github.com/FrontISTR/FEM_FrontISTR
master · Created: 2021-04-03 · Updated: 1 yr · 29 python files

Statistics

446
DL(Yr)
0
DL(Mo)
37
Stars
0
Issues
Manifest
Branch
master
Version
0.2.0
License
LGPL-2.1-or-later
Dependencies 8
  • Internal: Draft
  • Internal: Fem
  • Internal: Mesh
  • Internal: PySide
  • Internal: Sketcher
  • Pip: numpy
  • Pip: six
  • Warn: femtools (Not in AddonManager allowed packages)
Static Analysis 17
HIGH 5
fistrtools.py4
  • line 456: subprocess call with shell=True identified, security issue.
  • line 609: subprocess call with shell=True identified, security issue.
  • line 735: subprocess call with shell=True identified, security issue.
  • line 788: subprocess call with shell=True identified, security issue.
task_solver_fistrtools.py1
  • line 369: subprocess call with shell=True identified, security issue.
MEDIUM 1
fistrtools.py1
  • line 645: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 11
femsolver_FrontISTR/tasks.py2
  • line 35: Consider possible security implications associated with the subprocess module.
  • line 88: subprocess call - check for execution of untrusted input.
fistrtools.py8
  • line 35: Consider possible security implications associated with the subprocess module.
  • line 430: Consider possible security implications associated with the subprocess module.
  • line 513: Starting a process with a partial executable path
  • line 513: subprocess call with shell=True seems safe, but may be changed in the future, consider rewriting without shell
  • line 531: Starting a process with a partial executable path
  • line 531: subprocess call with shell=True seems safe, but may be changed in the future, consider rewriting without shell
  • line 547: Starting a process with a partial executable path
  • line 547: subprocess call with shell=True seems safe, but may be changed in the future, consider rewriting without shell
task_solver_fistrtools.py1
  • line 343: Consider possible security implications associated with the subprocess module.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
FrontISTR-Commons

Reinforcement master

v0.6· A workbench that provides tools for Reinforcement Generation and its Detailing.

82.7 / 100

Repository

https://github.com/amrit3701/FreeCAD-Reinforcement
master · Created: 2017-04-09 · Updated: 7 mo · 66 python files

Statistics

2,708
DL(Yr)
326
DL(Mo)
66
Stars
60
Issues
Manifest
Branch
master
Version
v0.6
License
LGPL-2.1-or-later
Dependencies 5
  • Compat: PySide6
  • Internal: Arch
  • Internal: Draft
  • Internal: PySide
  • Pip: Pillow
Static Analysis 36
HIGH 1
package.xml1
  • line 7: Missing license file 'None'
MEDIUM 12
BarBendingSchedule/BBSfunc.py1
  • line 337: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
BillOfMaterial/BillOfMaterialContent.py3
  • line 308: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 355: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 449: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
BillOfMaterial/BillOfMaterial_SVG.py3
  • line 998: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 1052: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 1063: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
RebarShapeCutList/RebarShapeCutListfunc.py2
  • line 806: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 1282: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
ReinforcementDrawing/ReinforcementDrawingfunc.py3
  • line 802: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 818: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 845: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 23
BarBendingSchedule/BBSfunc.py2
  • line 36: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 37: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
BillOfMaterial/BillOfMaterialContent.py1
  • line 30: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
BillOfMaterial/BillOfMaterial_SVG.py2
  • line 35: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 36: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
RebarShapeCutList/RebarShapeCutListfunc.py2
  • line 31: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 32: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
ReinforcementDrawing/ReinforcementDimensioning.py1
  • line 29: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
ReinforcementDrawing/ReinforcementDimensioningfunc.py10
  • line 30: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 652: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 680: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1026: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1054: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1441: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1469: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1860: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 1888: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 2284: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
ReinforcementDrawing/ReinforcementDrawingView.py1
  • line 29: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
ReinforcementDrawing/ReinforcementDrawingfunc.py1
  • line 30: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
SVGfunc.py1
  • line 31: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
license.*1
  • File not found.
package.xml1
  • line 9: Icon file 'icons/Reinforcement.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Amritpal Singh (amrit3701)

Rocket master

3.3.0· A workbench for designing model rockets.

81.5 / 100

Repository

https://github.com/davesrocketshop/Rocket
v3.3.0 · v3.3.0 · Created: 2021-02-01 · Updated: 3 yr · 266 python files

Statistics

0
DL(Yr)
0
DL(Mo)
79
Stars
10
Issues
Manifest
Branch
master
Version
3.3.0
License
LGPLv2.1
Dependencies 8
  • Compat: PySide2
  • Internal: Fem
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: matplotlib
  • Pip: numpy
  • Warn: pycurl (Not in AddonManager allowed packages)
Static Analysis 15
HIGH 4
util/updateTranslations.py3
  • line 141: Starting a process with a shell, possible injection detected, security issue.
  • line 181: Starting a process with a shell, possible injection detected, security issue.
  • line 201: Starting a process with a shell, possible injection detected, security issue.
package.xml1
  • Declared branch 'master' does not match git branch 'v3.3.0'
MEDIUM 6
Rocket/Importer/OpenRocket/OpenRocket.py1
  • line 157: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Rocket/Importer/RASAero/RASAero.py1
  • line 182: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Rocket/Parts/Material.py1
  • line 161: Possible SQL injection vector through string-based query construction.
Rocket/Parts/PartDatabase.py1
  • line 142: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
util/updateTranslations.py2
  • line 194: Using xml.sax.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 215: Using xml.sax.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 5
Rocket/Importer/OpenRocket/OpenRocket.py1
  • line 33: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Rocket/Importer/RASAero/RASAero.py1
  • line 33: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Rocket/Parts/PartDatabase.py1
  • line 31: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Rocket/Parts/PartDatabaseOrcImporter.py1
  • line 29: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
util/updateTranslations.py1
  • line 54: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
David Carter

freecad.optics_design_workbench master

1.2.8· Physically accurate forward ray tracing for optics simulation and optimization with FreeCAD workbench frontend.

78.8 / 100

Repository

https://github.com/zaphB/freecad.optics_design_workbench
master · Created: 2024-07-17 · Updated: 16 d · 73 python files

Statistics

2,078
DL(Yr)
345
DL(Mo)
16
Stars
0
Issues
Manifest
Branch
master
Version
1.2.8
License
LGPL-3.0-or-later
Dependencies 17
  • Compat: PySide2
  • Compat: PySide6
  • Internal: PySide
  • Pip: PyYAML
  • Pip: atomicwrites
  • Pip: cloudpickle
  • Pip: docutils
  • Pip: matplotlib
  • Pip: numpy
  • Pip: pandas
  • Pip: pyzmq
  • Pip: scipy
  • Pip: sympy
  • Warn: nbconvert (Not in AddonManager allowed packages)
  • Warn: nbformat (Not in AddonManager allowed packages)
  • Warn: pytest (Not in AddonManager allowed packages)
  • Warn: seaborn (Not in AddonManager allowed packages)
Static Analysis 60
HIGH 4
test/00-pure-python/0-install-package.py1
  • line 18: subprocess call with shell=True identified, security issue.
test/00-pure-python/1-build-docs.py1
  • line 17: subprocess call with shell=True identified, security issue.
test/30-run-examples/run-examples.py1
  • line 40: subprocess call with shell=True identified, security issue.
test/50-old-tests/run-simulations.py1
  • line 246: subprocess call with shell=True identified, security issue.
MEDIUM 4
freecad/optics_design_workbench/jupyter_utils/parameter_sweeper.py2
  • line 58: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 77: Probable insecure usage of temp file/directory.
test/22-global-placement/z-freecad-placements.py1
  • line 63: Use of possibly insecure function - consider using safer ast.literal_eval.
test/conftest.py1
  • line 37: Use of exec detected.
LOW 52
dev/update-packagexml.py3
  • line 3: Consider possible security implications associated with the subprocess module.
  • line 11: subprocess call - check for execution of untrusted input.
  • line 21: subprocess call - check for execution of untrusted input.
freecad/optics_design_workbench/detect_pyside.py3
  • line 8: Consider possible security implications associated with the subprocess module.
  • line 16: Starting a process with a partial executable path
  • line 16: subprocess call - check for execution of untrusted input.
freecad/optics_design_workbench/distributions/random_number_generator.py1
  • line 650: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/optics_design_workbench/freecad_elements/ray.py2
  • line 469: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 469: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/optics_design_workbench/freecad_elements/surface_source.py2
  • line 537: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 544: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/optics_design_workbench/io.py2
  • line 13: Consider possible security implications associated with pickle module.
  • line 152: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/optics_design_workbench/jupyter_utils/parameter_sweeper.py4
  • line 25: Consider possible security implications associated with pickle module.
  • line 77: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 82: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 689: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/optics_design_workbench/simulation/processes/simulation_loop.py3
  • line 36: Consider possible security implications associated with the subprocess module.
  • line 789: Starting a process with a partial executable path
  • line 789: subprocess call - check for execution of untrusted input.
freecad/optics_design_workbench/simulation/processes/worker_process.py4
  • line 12: Consider possible security implications associated with the subprocess module.
  • line 48: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 65: subprocess call - check for execution of untrusted input.
  • line 169: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/optics_design_workbench/simulation/results_store.py8
  • line 15: Consider possible security implications associated with pickle module.
  • line 280: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 281: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 467: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 477: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 486: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 697: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 730: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
test/00-pure-python/0-install-package.py1
  • line 8: Consider possible security implications associated with the subprocess module.
test/00-pure-python/1-build-docs.py1
  • line 8: Consider possible security implications associated with the subprocess module.
test/10-pure-python-notebooks/z-notebook-tests.py1
  • line 8: Consider possible security implications associated with the subprocess module.
test/20-freecad-document/2-from-fcstd-folder.py9
  • line 72: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 78: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 90: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 96: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 102: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 108: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 114: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 120: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 126: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
test/30-run-examples/run-examples.py1
  • line 10: Consider possible security implications associated with the subprocess module.
test/30-run-examples/z-notebook-tests.py1
  • line 8: Consider possible security implications associated with the subprocess module.
test/50-old-tests/run-simulations.py3
  • line 14: Consider possible security implications associated with the subprocess module.
  • line 17: Consider possible security implications associated with pickle module.
  • line 49: subprocess call - check for execution of untrusted input.
test/70-point-source-slow/z-notebook-tests.py1
  • line 8: Consider possible security implications associated with the subprocess module.
test/90-memory-leak-check/z-notebook-tests.py1
  • line 8: Consider possible security implications associated with the subprocess module.
package.xml1
  • line 17: Icon file 'workbench.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Philipp Bredol

Cfd

No description

77.3 / 100

Repository

https://github.com/qingfengxia/Cfd
master · Created: 2016-09-29 · Updated: 5 yr · 66 python files

Statistics

26
DL(Yr)
0
DL(Mo)
214
Stars
4
Issues
Dependencies 13
  • Compat: PySide2
  • Internal: Fem
  • Internal: Plot
  • Internal: PySide
  • Internal: pivy
  • Pip: matplotlib
  • Pip: numpy
  • Pip: six
  • Warn: FemTools (Not in AddonManager allowed packages)
  • Warn: PyFoam (Not in AddonManager allowed packages)
  • Warn: PyQt4 (Not in AddonManager allowed packages)
  • Warn: dolfin (Not in AddonManager allowed packages)
  • Warn: femtools (Not in AddonManager allowed packages)
Static Analysis 46
HIGH 5
FoamCaseBuilder/config.py1
  • line 23: subprocess call with shell=True identified, security issue.
FoamCaseBuilder/test/TestRunFoamApplication.py1
  • line 43: subprocess call with shell=True identified, security issue.
FoamCaseBuilder/utility.py1
  • line 454: subprocess call with shell=True identified, security issue.
importGmshMesh.py1
  • line 116: subprocess call with shell=True identified, security issue.
package.xml1
  • File not found.
MEDIUM 4
CfdExample.py1
  • line 80: Probable insecure usage of temp file/directory.
CfdTools.py2
  • line 75: Probable insecure usage of temp file/directory.
  • line 76: Probable insecure usage of temp file/directory.
FoamCaseBuilder/test/TestBuilder.py1
  • line 42: Probable insecure usage of temp file/directory.
LOW 37
CaeMesherGmsh.py2
  • line 29: Consider possible security implications associated with the subprocess module.
  • line 685: subprocess call - check for execution of untrusted input.
CfdFoamTools.py5
  • line 39: Consider possible security implications associated with the subprocess module.
  • line 45: Consider possible security implications associated with the subprocess module.
  • line 211: Consider possible security implications associated with the subprocess module.
  • line 302: Starting a process with a partial executable path
  • line 302: subprocess call - check for execution of untrusted input.
CfdRunnableFenics.py7
  • line 53: Consider possible security implications associated with the subprocess module.
  • line 58: Starting a process with a partial executable path
  • line 58: subprocess call - check for execution of untrusted input.
  • line 60: Starting a process with a partial executable path
  • line 60: subprocess call - check for execution of untrusted input.
  • line 62: Starting a process with a partial executable path
  • line 62: subprocess call - check for execution of untrusted input.
FoamCaseBuilder/BasicBuilder.py7
  • line 470: Consider possible security implications associated with the subprocess module.
  • line 474: Starting a process with a partial executable path
  • line 474: subprocess call - check for execution of untrusted input.
  • line 476: Starting a process with a partial executable path
  • line 476: subprocess call - check for execution of untrusted input.
  • line 478: Starting a process with a partial executable path
  • line 478: subprocess call - check for execution of untrusted input.
FoamCaseBuilder/config.py3
  • line 7: Consider possible security implications associated with the subprocess module.
  • line 75: subprocess call - check for execution of untrusted input.
  • line 131: subprocess call - check for execution of untrusted input.
FoamCaseBuilder/test/TestRunFoamApplication.py7
  • line 26: Consider possible security implications associated with the subprocess module.
  • line 88: subprocess call - check for execution of untrusted input.
  • line 129: Starting a process with a partial executable path
  • line 129: subprocess call - check for execution of untrusted input.
  • line 163: subprocess call - check for execution of untrusted input.
  • line 180: Starting a process with a partial executable path
  • line 180: subprocess call - check for execution of untrusted input.
FoamCaseBuilder/utility.py3
  • line 40: Consider possible security implications associated with the subprocess module.
  • line 58: subprocess call - check for execution of untrusted input.
  • line 64: subprocess call - check for execution of untrusted input.
cfdguiobjects/_TaskPanelCfdSolverControl.py1
  • line 36: Consider possible security implications associated with the subprocess module.
importGmshMesh.py1
  • line 34: Consider possible security implications associated with the subprocess module.
license.*1
  • File not found.
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 0

Corridor-Road main

1.1.0· FreeCAD workbench for parametric road corridor design, review, and output preparation.

77.2 / 100

Repository

https://github.com/ganadara135/CorridorRoad
main · Created: 2026-02-23 · Updated: 14 d · 660 python files

Statistics

130
DL(Yr)
0
DL(Mo)
11
Stars
1
Issues
Manifest
Branch
main
Version
1.1.0
License
LGPL-2.1-or-later
Dependencies 5
  • Compat: PySide2
  • Compat: PySide6
  • Internal: Mesh
  • Internal: PySide
  • Warn: pytest (Not in AddonManager allowed packages)
Static Analysis 181
HIGH 1
freecad/Corridor_Road/v1/exchange/ifc_export.py1
  • line 316: Use of weak SHA1 hash for security. Consider usedforsecurity=False
MEDIUM 2
freecad/Corridor_Road/v1/exchange/landxml_import.py2
  • line 30: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 61: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 172
freecad/Corridor_Road/objects/coord_transform.py1
  • line 71: Try, Except, Continue detected.
freecad/Corridor_Road/objects/corridor_segment_builder.py4
  • line 186: Possible hardcoded password: 'region'
  • line 188: Possible hardcoded password: 'structure'
  • line 190: Possible hardcoded password: 'notch'
  • line 297: Try, Except, Continue detected.
freecad/Corridor_Road/objects/obj_centerline3d_display.py5
  • line 432: Try, Except, Continue detected.
  • line 620: Try, Except, Continue detected.
  • line 652: Try, Except, Continue detected.
  • line 717: Try, Except, Continue detected.
  • line 850: Try, Except, Continue detected.
freecad/Corridor_Road/objects/obj_cut_fill_calc.py4
  • line 314: Try, Except, Continue detected.
  • line 345: Try, Except, Continue detected.
  • line 371: Try, Except, Continue detected.
  • line 689: Try, Except, Continue detected.
freecad/Corridor_Road/objects/obj_region_plan.py4
  • line 373: Try, Except, Continue detected.
  • line 385: Try, Except, Continue detected.
  • line 652: Try, Except, Continue detected.
  • line 922: Try, Except, Continue detected.
freecad/Corridor_Road/objects/obj_section_set.py13
  • line 58: Try, Except, Continue detected.
  • line 447: Try, Except, Continue detected.
  • line 470: Try, Except, Continue detected.
  • line 480: Try, Except, Continue detected.
  • line 1076: Try, Except, Continue detected.
  • line 3637: Try, Except, Continue detected.
  • line 3652: Try, Except, Continue detected.
  • line 3753: Try, Except, Continue detected.
  • line 3993: Try, Except, Continue detected.
  • line 4620: Try, Except, Continue detected.
  • line 5362: Possible hardcoded password: 'daylight=fallback:no_terrain'
  • line 5365: Possible hardcoded password: 'daylight=fallback:sampler_failed'
  • line 5371: Possible hardcoded password: 'daylight=off'
freecad/Corridor_Road/objects/obj_structure_set.py5
  • line 203: Try, Except, Continue detected.
  • line 218: Try, Except, Continue detected.
  • line 227: Try, Except, Continue detected.
  • line 229: Try, Except, Continue detected.
  • line 1162: Try, Except, Continue detected.
freecad/Corridor_Road/objects/sketch_alignment_import.py1
  • line 17: Try, Except, Continue detected.
freecad/Corridor_Road/objects/surface_sampling_core.py3
  • line 67: Try, Except, Continue detected.
  • line 79: Try, Except, Continue detected.
  • line 100: Try, Except, Continue detected.
freecad/Corridor_Road/objects/unit_policy.py2
  • line 150: Possible hardcoded password: 'm'
  • line 152: Possible hardcoded password: 'mm'
freecad/Corridor_Road/ui/task_alignment_editor.py1
  • line 871: Try, Except, Continue detected.
freecad/Corridor_Road/ui/task_centerline3d.py1
  • line 59: Try, Except, Continue detected.
freecad/Corridor_Road/ui/task_cross_section_editor.py2
  • line 1369: Try, Except, Continue detected.
  • line 1431: Try, Except, Continue detected.
freecad/Corridor_Road/ui/task_cross_section_viewer.py1
  • line 877: Try, Except, Continue detected.
freecad/Corridor_Road/ui/task_profile_editor.py1
  • line 122: Possible hardcoded password: 'custom'
freecad/Corridor_Road/ui/task_region_editor.py2
  • line 140: Possible hardcoded password: 'custom'
  • line 2835: Try, Except, Continue detected.
freecad/Corridor_Road/ui/task_section_generator.py2
  • line 183: Try, Except, Continue detected.
  • line 195: Try, Except, Continue detected.
freecad/Corridor_Road/ui/task_structure_editor.py3
  • line 193: Possible hardcoded password: 'custom'
  • line 2480: Try, Except, Continue detected.
  • line 2506: Try, Except, Continue detected.
freecad/Corridor_Road/ui/task_typical_section_editor.py1
  • line 237: Possible hardcoded password: 'custom'
freecad/Corridor_Road/v1/commands/cmd_build_corridor.py27
  • line 2278: Try, Except, Continue detected.
  • line 2618: Try, Except, Continue detected.
  • line 3060: Try, Except, Continue detected.
  • line 4514: Try, Except, Continue detected.
  • line 9516: Try, Except, Continue detected.
  • line 9617: Try, Except, Continue detected.
  • line 9654: Try, Except, Continue detected.
  • line 9680: Try, Except, Continue detected.
  • line 9772: Try, Except, Continue detected.
  • line 9801: Try, Except, Continue detected.
  • line 9831: Try, Except, Continue detected.
  • line 10975: Try, Except, Continue detected.
  • line 10990: Try, Except, Continue detected.
  • line 12812: Try, Except, Continue detected.
  • line 13895: Try, Except, Continue detected.
  • line 13973: Try, Except, Continue detected.
  • line 13984: Try, Except, Continue detected.
  • line 15769: Try, Except, Continue detected.
  • line 16082: Try, Except, Continue detected.
  • line 17923: Try, Except, Continue detected.
  • … 7 more issues
freecad/Corridor_Road/v1/commands/cmd_drainage_editor.py1
  • line 782: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_earthwork_balance.py1
  • line 48: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_edit_tin.py1
  • line 447: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_generate_applied_sections.py3
  • line 617: Try, Except, Continue detected.
  • line 680: Try, Except, Continue detected.
  • line 1341: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_intersection_editor.py3
  • line 2235: Try, Except, Continue detected.
  • line 2288: Try, Except, Continue detected.
  • line 2347: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_intersection_presets.py1
  • line 1273: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_profile_editor.py2
  • line 1566: Try, Except, Continue detected.
  • line 1713: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_region_editor.py2
  • line 596: Try, Except, Continue detected.
  • line 663: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_review_plan_profile.py4
  • line 52: Try, Except, Continue detected.
  • line 247: Try, Except, Continue detected.
  • line 337: Try, Except, Continue detected.
  • line 364: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_structure_editor.py1
  • line 2511: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_superelevation_editor.py1
  • line 601: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_view_sections.py4
  • line 873: Try, Except, Continue detected.
  • line 895: Try, Except, Continue detected.
  • line 923: Try, Except, Continue detected.
  • line 1199: Try, Except, Continue detected.
freecad/Corridor_Road/v1/commands/cmd_watertight_solids.py9
  • line 1947: Try, Except, Continue detected.
  • line 1960: Try, Except, Continue detected.
  • line 3002: Try, Except, Continue detected.
  • line 3006: Try, Except, Continue detected.
  • line 3101: Try, Except, Continue detected.
  • line 3497: Try, Except, Continue detected.
  • line 5360: Try, Except, Continue detected.
  • line 5770: Try, Except, Continue detected.
  • line 5797: Try, Except, Continue detected.
freecad/Corridor_Road/v1/exchange/landxml_import.py3
  • line 6: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 21: Possible hardcoded password: 'civil 3d'
  • line 373: Try, Except, Continue detected.
freecad/Corridor_Road/v1/objects/obj_alignment.py2
  • line 363: Try, Except, Continue detected.
  • line 401: Try, Except, Continue detected.
freecad/Corridor_Road/v1/objects/obj_quantity.py1
  • line 215: Try, Except, Continue detected.
freecad/Corridor_Road/v1/objects/obj_stationing.py1
  • line 349: Try, Except, Continue detected.
freecad/Corridor_Road/v1/objects/obj_subassembly_library.py1
  • line 307: Try, Except, Continue detected.
freecad/Corridor_Road/v1/objects/obj_subassembly_preset_library.py1
  • line 290: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/applied_section_service.py6
  • line 1126: Try, Except, Continue detected.
  • line 1310: Try, Except, Continue detected.
  • line 1377: Try, Except, Continue detected.
  • line 1410: Try, Except, Continue detected.
  • line 1849: Try, Except, Continue detected.
  • line 4283: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/corridor_solid_service.py2
  • line 265: Try, Except, Continue detected.
  • line 284: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/corridor_surface_geometry_service.py2
  • line 430: Try, Except, Continue detected.
  • line 516: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/corridor_surface_service.py1
  • line 375: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/earthwork_quantity_service.py1
  • line 104: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/intersection_patch_input_preparation_service.py1
  • line 214: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/intersection_slope_face_tin_builder_service.py1
  • line 1572: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/intersection_tin_clip_service.py3
  • line 515: Possible hardcoded password: 'span'
  • line 519: Try, Except, Continue detected.
  • line 635: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/roundabout_surface_builder_service.py1
  • line 1137: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/solid_target_discovery_service.py4
  • line 1015: Try, Except, Continue detected.
  • line 1028: Try, Except, Continue detected.
  • line 1072: Try, Except, Continue detected.
  • line 1082: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/builders/watertight_simulation_qa_service.py2
  • line 548: Try, Except, Continue detected.
  • line 728: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/alignment_curve_preview_service.py1
  • line 537: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/alignment_evaluation_service.py1
  • line 151: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/alignment_station_sampling_service.py1
  • line 168: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/centerline3d_evaluation_service.py1
  • line 221: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/centerline3d_source_geometry_service.py1
  • line 400: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/drainage_resolution_service.py1
  • line 1102: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/intersection_alignment_detection_service.py1
  • line 188: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/intersection_tie_in_edge_evaluation_service.py1
  • line 283: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/profile_earthwork_area_hint_service.py1
  • line 141: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/station_context_resolver.py1
  • line 99: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/subassembly_bench_row_parser.py1
  • line 119: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/surface_transition_validation_service.py1
  • line 152: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/evaluation/tin_sampling_service.py1
  • line 413: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/mapping/drainage_pipeline_network_mapper.py1
  • line 202: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/mapping/drainage_pipeline_solid_mapper.py1
  • line 53: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/mapping/exchange_output_mapper.py1
  • line 248: Try, Except, Continue detected.
freecad/Corridor_Road/v1/services/mapping/preview_audit_row_mapper.py1
  • line 63: Try, Except, Continue detected.
freecad/Corridor_Road/v1/ui/common/station_context.py1
  • line 59: Try, Except, Continue detected.
freecad/Corridor_Road/v1/ui/editors/subassembly_designer.py2
  • line 1667: Try, Except, Continue detected.
  • line 1718: Try, Except, Continue detected.
freecad/Corridor_Road/v1/ui/viewers/profile_review_view.py6
  • line 847: Try, Except, Continue detected.
  • line 933: Try, Except, Continue detected.
  • line 947: Try, Except, Continue detected.
  • line 1369: Try, Except, Continue detected.
  • line 1400: Try, Except, Continue detected.
  • line 1647: Try, Except, Continue detected.
tests/regression/smoke_centerline3d_display_segmentation.py1
  • line 43: Try, Except, Continue detected.
tests/regression/smoke_intersection_t_slope_face_surface.py2
  • line 161: Try, Except, Continue detected.
  • line 619: Try, Except, Continue detected.
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Kcod

WebTools master

1.0.0· A collection of tools to work with web services

76.3 / 100

Repository

https://github.com/yorikvanhavre/WebTools
master · Created: 2017-04-08 · Updated: 1 yr · 10 python files

Statistics

0
DL(Yr)
0
DL(Mo)
29
Stars
11
Issues
Manifest
Branch
master
Version
1.0.0
License
LGPL-2.1-or-later
Dependencies 7
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Pip: Requests
  • Warn: GitPython (Not in AddonManager allowed packages)
  • Warn: ifcopenshell (Not in AddonManager allowed packages)
  • Warn: importers (Not in AddonManager allowed packages)
Static Analysis 28
HIGH 1
package.xml1
  • line 10: Missing license file 'LICENSE'
MEDIUM 20
BIMServer.py11
  • line 141: Call to requests without timeout
  • line 178: Call to requests without timeout
  • line 191: Call to requests without timeout
  • line 220: Call to requests without timeout
  • line 246: Call to requests without timeout
  • line 263: Call to requests without timeout
  • line 271: Call to requests without timeout
  • line 282: Use of insecure and deprecated function (mktemp).
  • line 305: Call to requests without timeout
  • line 324: Use of insecure and deprecated function (mktemp).
  • line 338: Call to requests without timeout
Sketchfab.py3
  • line 258: Call to requests without timeout
  • line 301: Call to requests without timeout
  • line 343: Call to requests without timeout
Speckle.py6
  • line 31: Call to requests without timeout
  • line 42: Call to requests without timeout
  • line 53: Call to requests without timeout
  • line 63: Call to requests without timeout
  • line 116: Call to requests without timeout
  • line 133: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 7
Sketchfab.py1
  • line 46: Possible hardcoded password: 'https://sketchfab.com/settings/password'
Speckle.py1
  • line 23: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
tools/metadata.py3
  • line 22: Consider possible security implications associated with the subprocess module.
  • line 29: Consider possible security implications associated with the subprocess module.
  • line 30: subprocess call - check for execution of untrusted input.
license.*1
  • File not found.
package.xml1
  • line 14: Icon file 'icons/webTools.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Yorik van Havre

GDML Main

2.2.8· An external workbench for creating GDML models for Geant4 and Root

74.9 / 100

Repository

https://github.com/KeithSloan/GDML
Main · Created: 2019-11-21 · Updated: 1 mo · 78 python files

Statistics

832
DL(Yr)
0
DL(Mo)
72
Stars
50
Issues
Manifest
Branch
Main
Version
2.2.8
License
LGPL-2.1
Dependencies 12
  • Internal: BOPTools
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: Sketcher
  • Internal: Spreadsheet
  • Internal: pivy
  • Pip: gmsh
  • Pip: lxml
  • Pip: numpy
  • Warn: PyQt5 (Not in AddonManager allowed packages)
  • Warn: importers (Not in AddonManager allowed packages)
Static Analysis 53
MEDIUM 22
Utils.save/buildDirStruct.py1
  • line 17: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Utils/buildDirStruct.py1
  • line 17: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
benchmark/gen_all_gdml.py1
  • line 468: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
benchmark/gen_gmsh_new_defaults.py1
  • line 144: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
benchmark/gen_rect_cyl_gdml.py1
  • line 374: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
freecad/gdml/GDMLObjects.py1
  • line 498: Probable insecure usage of temp file/directory.
freecad/gdml/GDMLShared.py12
  • line 141: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 231: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 280: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 344: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1010: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1266: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1269: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1272: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1389: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1390: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1395: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1400: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/gdml/GmshUtils.py1
  • line 178: Probable insecure usage of temp file/directory.
freecad/gdml/exportGDML.py1
  • line 1453: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
freecad/gdml/importGDML.py2
  • line 3087: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 3596: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
LOW 31
CommandLine/convertObj.py1
  • line 279: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Macros/calcCenterOfMass.py3
  • line 125: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 126: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 127: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
Utils.save/buildDirStruct.py1
  • line 15: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Utils.save/convertObj.py1
  • line 237: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Utils/buildDirStruct.py1
  • line 15: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Utils/calcCenterOfMass.py3
  • line 125: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 126: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 127: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
benchmark/gen_all_gdml.py2
  • line 21: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 22: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
benchmark/gen_gmsh_new_defaults.py2
  • line 15: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 16: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
benchmark/gen_rect_cyl_gdml.py2
  • line 35: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 36: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/gdml/GDMLObjects.py3
  • line 4907: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 4907: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 4907: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/gdml/exportGDML.py2
  • line 61: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 6322: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/gdml/exportOpenMC.py2
  • line 67: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 6601: Try, Except, Continue detected.
freecad/gdml/importGDML.py2
  • line 3079: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 3589: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/gdml/preProcessLoops.py1
  • line 13: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/gdml/tests/issue_151_default_material/test_default_material.py2
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 18: subprocess call - check for execution of untrusted input.
freecad/gdml/tests/issue_164_external_file/test_external_file_import.py2
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 19: subprocess call - check for execution of untrusted input.
package.xml1
  • line 17: Icon file 'freecad/gdml/Resources/icons/GDMLWorkbench.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Keith Sloan

boltsfc main

2022.11.5· Installable FreeCAD package of BOLTS, an Open Library for Technical Specifications.

69.8 / 100

Repository

https://github.com/boltsparts/boltsfc
main · Created: 2017-07-02 · Updated: 4 yr · 51 python files

Statistics

8,409
DL(Yr)
1,088
DL(Mo)
41
Stars
3
Issues
Manifest
Branch
main
Version
2022.11.5
License
LGPLv2.1
Dependencies 3
  • Internal: Arch
  • Internal: PySide
  • Pip: PyYAML
Static Analysis 26
HIGH 3
package.xml3
  • line 2: Expecting an element content, got nothing
  • line 2: Invalid sequence in interleave
  • line 2: Element package failed to validate content
MEDIUM 21
BOLTS/bolttools/test_blt.py1
  • line 26: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
BOLTS/bolttools/test_common.py19
  • line 111: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 119: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 128: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 179: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 189: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 200: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 204: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 213: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 278: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 297: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 309: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 321: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 334: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 348: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 355: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 361: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 366: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 377: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
  • line 384: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
BOLTS/bolttools/yaml_in_yaml.py1
  • line 63: Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load().
LOW 2
license.*1
  • File not found.
package.xml1
  • line 22: Icon file 'BOLTS/icons/BOLTS_logo.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • No Mod init scripts found
Authors/Maintainers 1
Bernd Hahnebach

Ondsel-Lens main

2025.12.22.01· Workspace manager for Ondsel Lens workspaces

68.4 / 100

Repository

https://github.com/FreeCAD/Ondsel-Lens-Addon
main · Created: 2025-06-22 · Updated: 10 mo · 66 python files

Statistics

0
DL(Yr)
0
DL(Mo)
11
Stars
15
Issues
Manifest
Branch
main
Version
2025.12.22.01
License
LGPL-2.0-or-later, Apache-2.0, CC0-1.0, CC-BY-SA-2.0, CC-BY-SA-4.0
Dependencies 5
  • Internal: PySide
  • Pip: PyJWT
  • Pip: Requests
  • Pip: tzlocal
  • Warn: config (Not in AddonManager allowed packages)
Static Analysis 25
HIGH 6
register_lens_handler.py1
  • line 112: Starting a process with a shell, possible injection detected, security issue.
package.xml5
  • line 15: Missing license file 'None'
  • line 16: Missing license file 'None'
  • line 17: Missing license file 'None'
  • line 18: Missing license file 'None'
  • line 19: Missing license file 'None'
MEDIUM 13
APIClient.py7
  • line 240: Call to requests without timeout
  • line 264: Call to requests without timeout
  • line 284: Call to requests without timeout
  • line 308: Call to requests without timeout
  • line 335: Call to requests without timeout
  • line 354: Call to requests without timeout
  • line 369: Call to requests without timeout
Utils.py1
  • line 260: Call to requests without timeout
VersionModel.py1
  • line 142: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Workspace.py1
  • line 508: Call to requests without timeout
check_links.py1
  • line 16: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
delegates/curation_display_delegate.py1
  • line 193: Call to requests without timeout
integrations/reloadablefile/reloadable.py1
  • line 201: Call to requests without timeout
LOW 6
VersionModel.py1
  • line 9: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
WorkspaceView.py2
  • line 754: Possible hardcoded password: ''
  • line 2834: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
check_links.py1
  • line 6: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
components/login_dialog.py1
  • line 44: Possible hardcoded password: ''
package.xml1
  • line 22: Icon file 'Resources/icons/OndselWorkbench.svg' is too big (>16kB)
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
Pieter Hijma

Rocket master

5.1.3· Workbench for designing model rockets.

67.8 / 100

Repository

https://github.com/davesrocketshop/Rocket
master · v5.1.3 · Created: 2021-02-01 · Updated: 2 mo · 312 python files

Statistics

1,892
DL(Yr)
392
DL(Mo)
79
Stars
10
Issues
Manifest
Branch
master
Version
5.1.3
License
LGPL-2.1-or-later, MIT
Dependencies 10
  • Internal: Fem
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: Shapely
  • Pip: matplotlib
  • Pip: numpy
  • Warn: Materials (Not in AddonManager allowed packages)
  • Warn: docx (Not in AddonManager allowed packages)
  • Warn: pycurl (Not in AddonManager allowed packages)
Static Analysis 51
HIGH 5
util/updateTranslations.py3
  • line 141: Starting a process with a shell, possible injection detected, security issue.
  • line 181: Starting a process with a shell, possible injection detected, security issue.
  • line 201: Starting a process with a shell, possible injection detected, security issue.
util/updatets.py1
  • line 193: Starting a process with a shell, possible injection detected, security issue.
package.xml1
  • line 83: Missing license file 'LICENSE-CODE'
MEDIUM 14
Rocket/Importer/OpenRocket/OpenRocket.py1
  • line 167: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Rocket/Importer/RASAero/RASAero.py1
  • line 185: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Rocket/Importer/Rocksim/Rocksim.py1
  • line 198: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Rocket/Parts/BodyTube.py3
  • line 109: Possible SQL injection vector through string-based query construction.
  • line 115: Possible SQL injection vector through string-based query construction.
  • line 142: Possible SQL injection vector through string-based query construction.
Rocket/Parts/Material.py1
  • line 171: Possible SQL injection vector through string-based query construction.
Rocket/Parts/NoseCone.py1
  • line 134: Possible SQL injection vector through string-based query construction.
Rocket/Parts/PartDatabase.py1
  • line 177: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
Rocket/Parts/Transition.py1
  • line 158: Possible SQL injection vector through string-based query construction.
util/updateTranslations.py2
  • line 194: Using xml.sax.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 215: Using xml.sax.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
util/updatecrowdin.py2
  • line 142: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 188: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
LOW 30
Rocket/Importer/OpenRocket/OpenRocket.py1
  • line 36: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Rocket/Importer/RASAero/RASAero.py1
  • line 36: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Rocket/Importer/Rocksim/Rocksim.py1
  • line 32: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Rocket/Parts/PartDatabase.py1
  • line 34: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
Rocket/Parts/PartDatabaseOrcImporter.py1
  • line 34: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
util/updateTranslations.py1
  • line 54: Using xml.sax to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
util/updatecrowdin.py3
  • line 74: Consider possible security implications associated with the subprocess module.
  • line 350: Starting a process with a partial executable path
  • line 350: subprocess call - check for execution of untrusted input.
util/updatets.py23
  • line 51: Consider possible security implications associated with the subprocess module.
  • line 86: Starting a process with a partial executable path
  • line 86: subprocess call - check for execution of untrusted input.
  • line 98: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 98: Starting a process with a partial executable path
  • line 103: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 103: Starting a process with a partial executable path
  • line 113: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 113: Starting a process with a partial executable path
  • line 115: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 115: Starting a process with a partial executable path
  • line 119: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 119: Starting a process with a partial executable path
  • line 121: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 121: Starting a process with a partial executable path
  • line 125: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 125: Starting a process with a partial executable path
  • line 129: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 129: Starting a process with a partial executable path
  • line 139: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • … 3 more issues
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 1
David Carter

EMStudio master

1.13.0· RF and electromagnetic modeling and simulation inside FreeCAD. EMStudio provides a guided workflow (geometry - materials - ports/boundaries ...

63.8 / 100

Repository

https://github.com/king-aj3/EMStudioFree
master · Created: 2026-07-27 · Updated: today · 285 python files

Statistics

1,226
DL(Yr)
588
DL(Mo)
7
Stars
0
Issues
Manifest
Branch
master
Version
1.13.0
License
LGPL-2.1-or-later
Dependencies 5
  • Internal: Mesh
  • Internal: PySide
  • Pip: matplotlib
  • Pip: numpy
  • Pip: scipy
Static Analysis 110
MEDIUM 28
emstudio/coverage/itu_maps.py1
  • line 174: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
emstudio/setup/solvers.py2
  • line 713: Probable insecure usage of temp file/directory.
  • line 1804: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
emstudio/solvers/elmer/parser.py1
  • line 140: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
emstudio/solvers/nec2/writer.py1
  • line 304: Possible SQL injection vector through string-based query construction.
tests/smoke.py9
  • line 433: Use of exec detected.
  • line 632: Chmod setting a permissive mask 0o755 on file (exe).
  • line 655: Chmod setting a permissive mask 0o755 on file (exe).
  • line 817: Chmod setting a permissive mask 0o755 on file (fake).
  • line 1548: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 1582: Probable insecure usage of temp file/directory.
  • line 1582: Probable insecure usage of temp file/directory.
  • line 2584: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 2625: Use of exec detected.
tests/validation/bh_elmer.py1
  • line 235: Probable insecure usage of temp file/directory.
tests/validation/coverage.py1
  • line 697: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
tests/validation/element_designer.py3
  • line 814: Use of insecure and deprecated function (mktemp).
  • line 849: Use of insecure and deprecated function (mktemp).
  • line 890: Use of insecure and deprecated function (mktemp).
tests/validation/heat_ktemp_elmer.py1
  • line 73: Probable insecure usage of temp file/directory.
tests/validation/heat_radiation_elmer.py1
  • line 80: Probable insecure usage of temp file/directory.
tests/validation/heat_sigma_elmer.py1
  • line 102: Probable insecure usage of temp file/directory.
tests/validation/pattern_vtu.py3
  • line 40: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 51: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 57: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
tests/validation/solver_progress.py1
  • line 205: Use of exec detected.
tests/validation/team7_elmer.py1
  • line 119: Probable insecure usage of temp file/directory.
tests/validation/whitney3d_elmer.py1
  • line 146: Probable insecure usage of temp file/directory.
LOW 82
emstudio/meshing/gmsh_3d.py2
  • line 64: Consider possible security implications associated with the subprocess module.
  • line 488: subprocess call - check for execution of untrusted input.
emstudio/post/vtk_out.py1
  • line 378: Try, Except, Continue detected.
emstudio/procutil.py1
  • line 25: Consider possible security implications associated with the subprocess module.
emstudio/setup/accel.py2
  • line 38: Consider possible security implications associated with the subprocess module.
  • line 57: subprocess call - check for execution of untrusted input.
emstudio/setup/openfoam.py11
  • line 46: Consider possible security implications associated with the subprocess module.
  • line 495: subprocess call - check for execution of untrusted input.
  • line 660: subprocess call - check for execution of untrusted input.
  • line 735: subprocess call - check for execution of untrusted input.
  • line 739: Try, Except, Continue detected.
  • line 759: subprocess call - check for execution of untrusted input.
  • line 920: subprocess call - check for execution of untrusted input.
  • line 936: subprocess call - check for execution of untrusted input.
  • line 1075: subprocess call - check for execution of untrusted input.
  • line 1159: subprocess call - check for execution of untrusted input.
  • line 1225: subprocess call - check for execution of untrusted input.
emstudio/setup/solvers.py15
  • line 27: Consider possible security implications associated with the subprocess module.
  • line 586: subprocess call - check for execution of untrusted input.
  • line 810: Starting a process with a partial executable path
  • line 810: subprocess call - check for execution of untrusted input.
  • line 847: Starting a process with a partial executable path
  • line 847: subprocess call - check for execution of untrusted input.
  • line 1698: subprocess call - check for execution of untrusted input.
  • line 1730: subprocess call - check for execution of untrusted input.
  • line 1751: subprocess call - check for execution of untrusted input.
  • line 1759: subprocess call - check for execution of untrusted input.
  • line 1835: subprocess call - check for execution of untrusted input.
  • line 1860: subprocess call - check for execution of untrusted input.
  • line 1919: subprocess call - check for execution of untrusted input.
  • line 1931: subprocess call - check for execution of untrusted input.
  • line 2290: subprocess call - check for execution of untrusted input.
emstudio/solvers/base.py2
  • line 23: Consider possible security implications associated with the subprocess module.
  • line 95: subprocess call - check for execution of untrusted input.
emstudio/solvers/elmer/parser.py1
  • line 20: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
emstudio/solvers/nec2/writer.py1
  • line 104: Try, Except, Continue detected.
emstudio/solvers/openfoam/runner.py5
  • line 28: Consider possible security implications associated with the subprocess module.
  • line 120: Starting a process with a partial executable path
  • line 120: subprocess call - check for execution of untrusted input.
  • line 125: subprocess call - check for execution of untrusted input.
  • line 305: subprocess call - check for execution of untrusted input.
emstudio/solvers/openfoam/vtk_export.py2
  • line 115: Consider possible security implications associated with the subprocess module.
  • line 119: subprocess call - check for execution of untrusted input.
tests/run_pro_freecad.py3
  • line 51: Consider possible security implications associated with the subprocess module.
  • line 64: subprocess call - check for execution of untrusted input.
  • line 172: subprocess call - check for execution of untrusted input.
tests/smoke.py12
  • line 221: Consider possible security implications associated with the subprocess module.
  • line 283: subprocess call - check for execution of untrusted input.
  • line 316: Consider possible security implications associated with the subprocess module.
  • line 341: subprocess call - check for execution of untrusted input.
  • line 596: Consider possible security implications associated with the subprocess module.
  • line 616: subprocess call - check for execution of untrusted input.
  • line 776: Consider possible security implications associated with the subprocess module.
  • line 869: Consider possible security implications associated with the subprocess module.
  • line 965: subprocess call - check for execution of untrusted input.
  • line 972: subprocess call - check for execution of untrusted input.
  • line 1544: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 2576: Using xml.dom.minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
tests/validation/coverage.py1
  • line 696: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
tests/validation/isolation_openems.py2
  • line 26: Consider possible security implications associated with the subprocess module.
  • line 95: subprocess call - check for execution of untrusted input.
tests/validation/isolation_patch_openems.py2
  • line 28: Consider possible security implications associated with the subprocess module.
  • line 86: subprocess call - check for execution of untrusted input.
tests/validation/litz_noscipy.py2
  • line 58: Consider possible security implications associated with the subprocess module.
  • line 156: subprocess call - check for execution of untrusted input.
tests/validation/openfoam_runner_cancel.py6
  • line 39: Consider possible security implications associated with the subprocess module.
  • line 99: Starting a process with a partial executable path
  • line 99: subprocess call - check for execution of untrusted input.
  • line 122: Starting a process with a partial executable path
  • line 122: subprocess call - check for execution of untrusted input.
  • line 225: subprocess call - check for execution of untrusted input.
tests/validation/palace_radiation.py3
  • line 48: Consider possible security implications associated with the subprocess module.
  • line 114: subprocess call - check for execution of untrusted input.
  • line 133: subprocess call - check for execution of untrusted input.
tests/validation/pattern_vtu.py1
  • line 21: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
tests/validation/run_battery.py2
  • line 31: Consider possible security implications associated with the subprocess module.
  • line 444: subprocess call - check for execution of untrusted input.
tests/validation/team7_elmer.py3
  • line 217: Consider possible security implications associated with the subprocess module.
  • line 222: subprocess call - check for execution of untrusted input.
  • line 224: subprocess call - check for execution of untrusted input.
tests/validation/waveguide_port_openems.py2
  • line 58: Consider possible security implications associated with the subprocess module.
  • line 144: subprocess call - check for execution of untrusted input.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
ajj3.us

AnimationFreeCAD main

1.0-beta· The FreeCAD Animation workbench allows users to animate any object easily through visual scripting Nodes thanks to PyFlow.

44.1 / 100

Repository

https://github.com/QuentinTournier40/AnimationFreeCAD
main · Created: 2022-01-29 · Updated: 2 yr · 630 python files

Statistics

3,081
DL(Yr)
403
DL(Mo)
33
Stars
10
Issues
Manifest
Branch
main
Version
1.0-beta
License
Apache-2.0
Dependencies 21
  • Compat: PySide2
  • Compat: shiboken2
  • Internal: Draft
  • Internal: PySide
  • Pip: Pillow
  • Pip: Pygments
  • Pip: lxml
  • Pip: numpy
  • Pip: six
  • Warn: ConfigParser (Not in AddonManager allowed packages)
  • Warn: Image (Not in AddonManager allowed packages)
  • Warn: PyQt4 (Not in AddonManager allowed packages)
  • Warn: PyQt5 (Not in AddonManager allowed packages)
  • Warn: Sphinx (Not in AddonManager allowed packages)
  • Warn: aenum (Not in AddonManager allowed packages)
  • Warn: nose (Not in AddonManager allowed packages)
  • Warn: opencv-python (Not in AddonManager allowed packages)
  • Warn: recommonmark (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
  • Warn: shiboken (Not in AddonManager allowed packages)
  • Warn: sip (Not in AddonManager allowed packages)
Static Analysis 105
HIGH 2
PyFlow/Packages/PyFlowBase/UI/UIPythonNode.py1
  • line 220: subprocess call with shell=True identified, security issue.
package.xml1
  • line 2: Expecting a namespace for element package
MEDIUM 44
PyFlow/Core/PyCodeCompiler.py2
  • line 42: Use of exec detected.
  • line 64: Use of exec detected.
PyFlow/Packages/AnimationFreeCAD/Class/Rotation.py1
  • line 45: Use of exec detected.
PyFlow/Packages/AnimationFreeCAD/Class/TranslationAvecCourbe.py1
  • line 56: Use of exec detected.
PyFlow/Packages/AnimationFreeCAD/Class/TranslationTest.py1
  • line 56: Use of exec detected.
PyFlow/Packages/AnimationFreeCAD/Class/translationFormuleMathematiques.py5
  • line 26: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 27: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 28: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 48: Use of exec detected.
  • line 56: Use of exec detected.
requirements/Qt.py-master/examples/loadUi/baseinstance2.py3
  • line 35: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 45: Use of exec detected.
  • line 50: Use of possibly insecure function - consider using safer ast.literal_eval.
requirements/Qt.py-master/membership.py3
  • line 158: Use of exec detected.
  • line 167: Use of exec detected.
  • line 176: Use of exec detected.
requirements/blinker-master/tests/test_utilities.py1
  • line 23: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
requirements/docutils-0.18/docutils/utils/math/math2html.py1
  • line 3173: Use of possibly insecure function - consider using safer ast.literal_eval.
requirements/docutils-0.18/docutils/writers/docutils_xml.py1
  • line 84: Using xml.sax.make_parser to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.make_parser with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
requirements/docutils-0.18/docutils/writers/odf_odt/__init__.py6
  • line 758: Using xml.dom.minidom.parseString to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parseString with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 985: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 986: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 991: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 2688: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 2910: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
requirements/docutils-0.18/test/functional/tests/footnotes_html5.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_docutils_xml.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_html4css1.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_html5.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_latex.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_manpage.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_pseudoxml.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_s5_html_1.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_s5_html_2.py1
  • line 3: Use of exec detected.
requirements/docutils-0.18/test/functional/tests/standalone_rst_xetex.py1
  • line 2: Use of exec detected.
requirements/docutils-0.18/test/test_functional.py2
  • line 114: Use of exec detected.
  • line 116: Use of exec detected.
requirements/docutils-0.18/test/test_pickle.py1
  • line 23: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
requirements/docutils-0.18/test/test_publisher.py1
  • line 160: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
requirements/docutils-0.18/test/test_writers/test_odt.py1
  • line 107: Using xml.etree.ElementTree.fromstring to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.fromstring with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
requirements/docutils-0.18/tools/dev/create_unimap.py1
  • line 66: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
requirements/docutils-0.18/tools/dev/profile_docutils.py1
  • line 38: Use of exec detected.
requirements/nine-1.1.0/nine-1.1.0/nine/__init__.py1
  • line 52: Use of exec detected.
requirements/nine-1.1.0/nine/__init__.py1
  • line 52: Use of exec detected.
LOW 59
PyFlow/App.py3
  • line 21: Consider possible security implications associated with the subprocess module.
  • line 71: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 205: Try, Except, Continue detected.
PyFlow/Core/GraphBase.py1
  • line 235: Try, Except, Continue detected.
PyFlow/Packages/AnimationFreeCAD/Class/Exportation.py1
  • line 4: Consider possible security implications associated with FALSE module.
PyFlow/Packages/PyFlowBase/FunctionLibraries/DefaultLib.py4
  • line 55: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 55: Starting a process with a partial executable path
  • line 57: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 57: Starting a process with a partial executable path
PyFlow/Packages/PyFlowBase/FunctionLibraries/RandomLib.py1
  • line 36: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
PyFlow/Packages/PyFlowBase/Tools/LoggerTool.py2
  • line 30: Consider possible security implications associated with the subprocess module.
  • line 256: subprocess call - check for execution of untrusted input.
PyFlow/Packages/PyFlowBase/UI/UIPythonNode.py1
  • line 17: Consider possible security implications associated with the subprocess module.
PyFlow/UI/CompileUiQt.py2
  • line 18: Consider possible security implications associated with the subprocess module.
  • line 41: subprocess call - check for execution of untrusted input.
PyFlow/UI/EncodeResources.py2
  • line 18: Consider possible security implications associated with the subprocess module.
  • line 54: subprocess call - check for execution of untrusted input.
PyFlow/Wizards/PkgGen.py1
  • line 152: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
requirements/Qt.py-master/Qt.py1
  • line 942: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
requirements/Qt.py-master/examples/loadUi/baseinstance2.py1
  • line 32: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
requirements/Qt.py-master/run_tests.py5
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 43: subprocess call - check for execution of untrusted input.
  • line 47: subprocess call - check for execution of untrusted input.
  • line 50: subprocess call - check for execution of untrusted input.
  • line 53: subprocess call - check for execution of untrusted input.
requirements/Qt.py-master/tests.py9
  • line 9: Consider possible security implications associated with the subprocess module.
  • line 441: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 560: subprocess call - check for execution of untrusted input.
  • line 568: subprocess call - check for execution of untrusted input.
  • line 576: subprocess call - check for execution of untrusted input.
  • line 594: subprocess call - check for execution of untrusted input.
  • line 637: subprocess call - check for execution of untrusted input.
  • line 647: subprocess call - check for execution of untrusted input.
  • line 836: subprocess call - check for execution of untrusted input.
requirements/blinker-master/tests/test_utilities.py1
  • line 1: Consider possible security implications associated with pickle module.
requirements/docutils-0.18/docutils/nodes.py2
  • line 93: Using xml.dom.minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 1350: Using xml.dom.minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
requirements/docutils-0.18/docutils/utils/math/tex2mathml_extern.py8
  • line 19: Consider possible security implications associated with the subprocess module.
  • line 33: Starting a process with a partial executable path
  • line 33: subprocess call - check for execution of untrusted input.
  • line 49: Starting a process with a partial executable path
  • line 49: subprocess call - check for execution of untrusted input.
  • line 79: Starting a process with a partial executable path
  • line 79: subprocess call - check for execution of untrusted input.
  • line 121: subprocess call - check for execution of untrusted input.
requirements/docutils-0.18/docutils/utils/smartquotes.py1
  • line 568: Possible hardcoded password: ' '
requirements/docutils-0.18/docutils/writers/docutils_xml.py1
  • line 14: Using xml.sax.saxutils to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.sax.saxutils with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
requirements/docutils-0.18/docutils/writers/odf_odt/__init__.py4
  • line 19: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 20: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 1104: Starting a process with a shell: Seems safe, but may be changed in the future, consider rewriting without shell
  • line 1104: Starting a process with a partial executable path
requirements/docutils-0.18/docutils/writers/pep_html/__init__.py1
  • line 83: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
requirements/docutils-0.18/test/test_pickle.py1
  • line 12: Consider possible security implications associated with pickle module.
requirements/docutils-0.18/test/test_publisher.py1
  • line 11: Consider possible security implications associated with pickle module.
requirements/docutils-0.18/test/test_writers/test_odt.py1
  • line 36: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
requirements/docutils-0.18/tools/dev/create_unimap.py1
  • line 13: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
requirements/docutils-0.18/tools/test/test_buildhtml.py2
  • line 27: Consider possible security implications associated with the subprocess module.
  • line 39: subprocess call - check for execution of untrusted input.
package.xml1
  • line 14: Icon file 'icons/clapCinema.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses exec based layout
Authors/Maintainers 2
Andréas Cottet Quentin Tournier

workfeature-macro

No description

17.9 / 100

Repository

https://github.com/Rentlau/WorkFeature
master · Created: 2015-02-15 · Updated: 2 yr · 34 python files

Statistics

0
DL(Yr)
0
DL(Mo)
28
Stars
3
Issues
Dependencies 6
  • Compat: PySide2
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: pivy
  • Pip: numpy
Static Analysis 81
HIGH 1
package.xml1
  • File not found.
MEDIUM 34
WorkFeature/ParCurve/WF_ObjParCurve.py66
  • line 610: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 615: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 620: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 625: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 750: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 751: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 779: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 780: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 781: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 789: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 790: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 791: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 801: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 802: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 803: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 855: Use of exec detected.
  • line 894: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 895: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 896: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 942: Use of exec detected.
  • … 46 more issues
WorkFeature/ParCurve/WF_ObjParCurveEdit.py1
  • line 266: Use of possibly insecure function - consider using safer ast.literal_eval.
WorkFeature/WF.py12
  • line 1001: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 3804: Possible SQL injection vector through string-based query construction.
  • line 4199: Possible SQL injection vector through string-based query construction.
  • line 5727: Possible SQL injection vector through string-based query construction.
  • line 5805: Possible SQL injection vector through string-based query construction.
  • line 5806: Possible SQL injection vector through string-based query construction.
  • line 5807: Possible SQL injection vector through string-based query construction.
  • line 5808: Possible SQL injection vector through string-based query construction.
  • line 12983: Possible SQL injection vector through string-based query construction.
  • line 13084: Possible SQL injection vector through string-based query construction.
  • line 13421: Possible SQL injection vector through string-based query construction.
  • line 13478: Possible SQL injection vector through string-based query construction.
LOW 1
license.*1
  • File not found.
INFO 1
Layout1
  • No Mod init scripts found
Authors/Maintainers 0

AIGenFurniture main

0.2.0· Parametric furniture cabinet design workbench. Generate cabinets from simple boxes, apply features (fronts, shelves, drawers), and export ma...

0 / 100

Repository

https://github.com/yelloish6/AIGenFurniture-freecad-workbench
main · v0.2.0 · Created: 2025-08-27 · Updated: 5 d · 875 python files

Statistics

4,401
DL(Yr)
912
DL(Mo)
12
Stars
0
Issues
Manifest
Branch
main
Version
0.2.0
License
LGPL-2.1-or-later
Dependencies 35
  • Internal: Draft
  • Internal: PySide
  • Pip: Pillow
  • Pip: Pygments
  • Pip: defusedxml
  • Pip: fontTools
  • Pip: ipython
  • Pip: lxml
  • Pip: pandas
  • Pip: psutil
  • Pip: pytz
  • Pip: threadpoolctl
  • Warn: Cython (Not in AddonManager allowed packages)
  • Warn: Image (Not in AddonManager allowed packages)
  • Warn: PyInstaller (Not in AddonManager allowed packages)
  • Warn: Pyphen (Not in AddonManager allowed packages)
  • Warn: blessings (Not in AddonManager allowed packages)
  • Warn: checks (Not in AddonManager allowed packages)
  • Warn: cppyy (Not in AddonManager allowed packages)
  • Warn: freetype_py (Not in AddonManager allowed packages)
  • Warn: hypothesis (Not in AddonManager allowed packages)
  • Warn: ipykernel (Not in AddonManager allowed packages)
  • Warn: mtrand (Not in AddonManager allowed packages)
  • Warn: mypy (Not in AddonManager allowed packages)
  • Warn: new (Not in AddonManager allowed packages)
  • Warn: pyaes (Not in AddonManager allowed packages)
  • Warn: pylibdmtx (Not in AddonManager allowed packages)
  • Warn: pymupdf_fonts (Not in AddonManager allowed packages)
  • Warn: pytest (Not in AddonManager allowed packages)
  • Warn: rlPyCairo (Not in AddonManager allowed packages)
  • Warn: rlextra (Not in AddonManager allowed packages)
  • Warn: scipy_doctest (Not in AddonManager allowed packages)
  • Warn: sets (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
  • Warn: uharfbuzz (Not in AddonManager allowed packages)
Static Analysis 365
HIGH 7
freecad/AIGenFurniture/vendor/reportlab/lib/pdfencrypt.py6
  • line 344: Use of weak MD5 hash for security. Consider usedforsecurity=False
  • line 355: Use of weak MD5 hash for security. Consider usedforsecurity=False
  • line 373: Use of weak MD5 hash for security. Consider usedforsecurity=False
  • line 379: Use of weak MD5 hash for security. Consider usedforsecurity=False
  • line 395: Use of weak MD5 hash for security. Consider usedforsecurity=False
  • line 432: Use of weak MD5 hash for security. Consider usedforsecurity=False
freecad/AIGenFurniture/vendor_delete/pymupdf/__init__.py1
  • line 17841: subprocess call with shell=True identified, security issue.
MEDIUM 159
freecad/AIGenFurniture/vendor/numpy/__config__.py1
  • line 96: Probable insecure usage of temp file/directory.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test__exceptions.py2
  • line 19: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 84: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_arrayprint.py2
  • line 340: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 341: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_custom_dtypes.py1
  • line 308: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_datetime.py7
  • line 851: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 853: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 855: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 858: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 865: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 869: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 873: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_dtype.py4
  • line 1065: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1366: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1428: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1439: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_multiarray.py21
  • line 189: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1549: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1701: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1855: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1862: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1871: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1882: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 3939: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 4404: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4406: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4427: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4446: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4459: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4461: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4463: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4465: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4476: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4496: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4505: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 4559: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • … 1 more issues
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_overrides.py1
  • line 221: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_records.py9
  • line 170: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 171: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 173: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 414: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 415: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 421: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 422: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 429: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 453: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_regression.py16
  • line 52: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 363: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 489: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 833: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1069: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1082: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1275: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1277: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1907: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1919: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1931: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1957: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 1966: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 2212: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 2436: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 2567: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_scalarmath.py1
  • line 654: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_simd.py11
  • line 244: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 510: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 640: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 701: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 721: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 741: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 767: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 804: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 843: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 895: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1102: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_stringdtype.py1
  • line 366: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_ufunc.py5
  • line 204: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 209: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 216: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 226: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 501: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_umath.py2
  • line 513: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 577: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_umath_accuracy.py2
  • line 71: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 72: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/f2py/auxfuncs.py3
  • line 632: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 640: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 644: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/f2py/capi_maps.py3
  • line 159: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 296: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 449: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/f2py/crackfortran.py9
  • line 1329: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 2271: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 2559: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 2637: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 2646: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 2914: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 2985: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 3016: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 3468: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/lib/_datasource.py2
  • line 333: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 475: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
freecad/AIGenFurniture/vendor/numpy/lib/_format_impl.py1
  • line 838: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/lib/_npyio_impl.py1
  • line 494: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/ma/tests/test_core.py6
  • line 733: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 748: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 757: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 767: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 777: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 5547: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/ma/tests/test_mrecords.py1
  • line 293: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/ma/tests/test_old_ma.py1
  • line 621: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/matrixlib/tests/test_masked_matrix.py1
  • line 89: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/polynomial/tests/test_polynomial.py1
  • line 62: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_direct.py5
  • line 303: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 311: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 321: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 327: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 555: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_generator_mt19937.py3
  • line 2776: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 2782: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 2798: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_randomstate.py1
  • line 268: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_smoke.py2
  • line 437: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 443: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/numpy/testing/_private/utils.py2
  • line 1297: Use of exec detected.
  • line 1583: Use of exec detected.
freecad/AIGenFurniture/vendor/numpy/tests/test_public_api.py1
  • line 407: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/numpy/tests/test_reloading.py1
  • line 45: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/reportlab/graphics/widgets/grids.py1
  • line 517: Probable insecure usage of temp file/directory.
freecad/AIGenFurniture/vendor/reportlab/graphics/widgets/markers.py1
  • line 245: Probable insecure usage of temp file/directory.
freecad/AIGenFurniture/vendor/reportlab/lib/extformat.py1
  • line 48: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/reportlab/lib/fontfinder.py1
  • line 231: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/reportlab/lib/pdfencrypt.py2
  • line 723: Use of exec detected.
  • line 725: Use of exec detected.
freecad/AIGenFurniture/vendor/reportlab/lib/rl_accel.py1
  • line 26: Use of exec detected.
freecad/AIGenFurniture/vendor/reportlab/lib/rl_safe_eval.py2
  • line 1203: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1291: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/reportlab/lib/rltempfile.py1
  • line 37: Use of insecure and deprecated function (mktemp).
freecad/AIGenFurniture/vendor/reportlab/lib/testutils.py2
  • line 110: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 184: Use of possibly insecure function - consider using safer ast.literal_eval.
freecad/AIGenFurniture/vendor/reportlab/lib/utils.py4
  • line 122: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
  • line 476: Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
  • line 806: Deserialization with the marshal module is possibly dangerous.
  • line 907: Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.
freecad/AIGenFurniture/vendor/reportlab/pdfbase/cidfonts.py4
  • line 205: Deserialization with the marshal module is possibly dangerous.
  • line 206: Deserialization with the marshal module is possibly dangerous.
  • line 207: Deserialization with the marshal module is possibly dangerous.
  • line 208: Deserialization with the marshal module is possibly dangerous.
freecad/AIGenFurniture/vendor/reportlab/pdfgen/textobject.py2
  • line 56: Use of exec detected.
  • line 79: Use of exec detected.
freecad/AIGenFurniture/vendor/stl/stl.py2
  • line 496: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 505: Using xml.etree.ElementTree.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
freecad/AIGenFurniture/vendor/typing_extensions.py2
  • line 4034: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 4116: Use of possibly insecure function - consider using safer ast.literal_eval.
tests/test_community_export_boundary.py3
  • line 102: Probable insecure usage of temp file/directory.
  • line 112: Probable insecure usage of temp file/directory.
  • line 118: Probable insecure usage of temp file/directory.
LOW 167
freecad/AIGenFurniture/furniture_design/cabinets/features/__init__.py1
  • line 4: Consider possible security implications associated with ShelvesMixin module.
freecad/AIGenFurniture/vendor/et_xmlfile/incremental_tree.py1
  • line 44: Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor/et_xmlfile/xmlfile.py1
  • line 9: Using Element to parse untrusted XML data is known to be vulnerable to XML attacks. Replace Element with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor/numpy/_core/_methods.py1
  • line 7: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test__exceptions.py1
  • line 5: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_casting_unittests.py1
  • line 168: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_cpu_features.py5
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 29: Consider possible security implications associated with the subprocess module.
  • line 30: subprocess call - check for execution of untrusted input.
  • line 109: subprocess call - check for execution of untrusted input.
  • line 162: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_custom_dtypes.py1
  • line 303: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_cython.py9
  • line 2: Consider possible security implications associated with the subprocess module.
  • line 55: Starting a process with a partial executable path
  • line 55: subprocess call - check for execution of untrusted input.
  • line 61: Starting a process with a partial executable path
  • line 61: subprocess call - check for execution of untrusted input.
  • line 68: Starting a process with a partial executable path
  • line 68: subprocess call - check for execution of untrusted input.
  • line 73: Starting a process with a partial executable path
  • line 73: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_datetime.py1
  • line 2: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_dtype.py2
  • line 4: Consider possible security implications associated with pickle module.
  • line 1334: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_hashtable.py3
  • line 14: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 15: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 20: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_limited_api.py9
  • line 2: Consider possible security implications associated with the subprocess module.
  • line 53: Starting a process with a partial executable path
  • line 53: subprocess call - check for execution of untrusted input.
  • line 59: Starting a process with a partial executable path
  • line 59: subprocess call - check for execution of untrusted input.
  • line 67: Starting a process with a partial executable path
  • line 67: subprocess call - check for execution of untrusted input.
  • line 72: Starting a process with a partial executable path
  • line 72: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_multiarray.py2
  • line 12: Consider possible security implications associated with pickle module.
  • line 183: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_nditer.py2
  • line 1: Consider possible security implications associated with the subprocess module.
  • line 2094: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_overrides.py1
  • line 3: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_records.py1
  • line 2: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_regression.py1
  • line 3: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_stringdtype.py1
  • line 4: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_core/tests/test_ufunc.py1
  • line 3: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/_pyinstaller/tests/test_pyinstaller.py2
  • line 1: Consider possible security implications associated with the subprocess module.
  • line 34: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/f2py/__init__.py1
  • line 13: Consider possible security implications associated with the subprocess module.
freecad/AIGenFurniture/vendor/numpy/f2py/_backends/_meson.py2
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 179: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/f2py/tests/test_f2py2e.py5
  • line 4: Consider possible security implications associated with the subprocess module.
  • line 597: subprocess call - check for execution of untrusted input.
  • line 766: subprocess call - check for execution of untrusted input.
  • line 788: subprocess call - check for execution of untrusted input.
  • line 813: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/f2py/tests/util.py5
  • line 15: Consider possible security implications associated with the subprocess module.
  • line 50: Starting a process with a partial executable path
  • line 50: subprocess call - check for execution of untrusted input.
  • line 246: subprocess call - check for execution of untrusted input.
  • line 267: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/lib/_format_impl.py2
  • line 166: Consider possible security implications associated with pickle module.
  • line 613: Possible hardcoded password: 'L'
freecad/AIGenFurniture/vendor/numpy/lib/_npyio_impl.py1
  • line 9: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/lib/tests/test_format.py4
  • line 409: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 941: Consider possible security implications associated with the subprocess module.
  • line 942: Starting a process with a partial executable path
  • line 942: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/linalg/tests/test_linalg.py3
  • line 6: Consider possible security implications associated with the subprocess module.
  • line 2053: subprocess call - check for execution of untrusted input.
  • line 2058: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/ma/tests/test_core.py1
  • line 11: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/ma/tests/test_mrecords.py1
  • line 7: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/ma/tests/test_old_ma.py1
  • line 1: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/matrixlib/tests/test_masked_matrix.py1
  • line 1: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/polynomial/tests/test_polynomial.py1
  • line 4: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_direct.py3
  • line 298: Consider possible security implications associated with pickle module.
  • line 317: Consider possible security implications associated with pickle module.
  • line 540: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_extending.py7
  • line 3: Consider possible security implications associated with the subprocess module.
  • line 76: Starting a process with a partial executable path
  • line 76: subprocess call - check for execution of untrusted input.
  • line 83: Starting a process with a partial executable path
  • line 83: subprocess call - check for execution of untrusted input.
  • line 87: Starting a process with a partial executable path
  • line 87: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_generator_mt19937.py53
  • line 760: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 767: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 772: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 780: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 789: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 801: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 807: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 813: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 816: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 822: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 828: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 834: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 840: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 865: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 866: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 867: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 868: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 869: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 870: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 874: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • … 33 more issues
freecad/AIGenFurniture/vendor/numpy/random/tests/test_randomstate.py1
  • line 2: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/random/tests/test_smoke.py1
  • line 1: Consider possible security implications associated with pickle module.
freecad/AIGenFurniture/vendor/numpy/testing/_private/extbuild.py7
  • line 9: Consider possible security implications associated with the subprocess module.
  • line 230: Starting a process with a partial executable path
  • line 230: subprocess call - check for execution of untrusted input.
  • line 236: Starting a process with a partial executable path
  • line 236: subprocess call - check for execution of untrusted input.
  • line 242: Starting a process with a partial executable path
  • line 242: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/testing/_private/utils.py2
  • line 1426: Consider possible security implications associated with the subprocess module.
  • line 1429: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/tests/test_configtool.py3
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 22: Starting a process with a partial executable path
  • line 22: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/tests/test_public_api.py2
  • line 5: Consider possible security implications associated with the subprocess module.
  • line 65: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/tests/test_reloading.py3
  • line 1: Consider possible security implications associated with pickle module.
  • line 2: Consider possible security implications associated with the subprocess module.
  • line 70: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/numpy/tests/test_scripts.py3
  • line 6: Consider possible security implications associated with the subprocess module.
  • line 42: subprocess call - check for execution of untrusted input.
  • line 48: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/openpyxl/formula/tokenizer.py1
  • line 43: Possible hardcoded password: ',;}) +-*/^&=><%'
freecad/AIGenFurniture/vendor/openpyxl/utils/protection.py1
  • line 4: Possible hardcoded password: ''
freecad/AIGenFurniture/vendor/openpyxl/xml/functions.py2
  • line 28: Using Element to parse untrusted XML data is known to be vulnerable to XML attacks. Replace Element with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 40: Using iterparse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace iterparse with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor/python_utils/decorators.py1
  • line 170: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/AIGenFurniture/vendor/python_utils/terminal.py5
  • line 129: Consider possible security implications associated with the subprocess module.
  • line 131: Starting a process with a partial executable path
  • line 131: subprocess call - check for execution of untrusted input.
  • line 139: Starting a process with a partial executable path
  • line 139: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/reportlab/graphics/renderPM.py1
  • line 786: Using escape to parse untrusted XML data is known to be vulnerable to XML attacks. Replace escape with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor/reportlab/lib/extformat.py2
  • line 44: Possible hardcoded password: '('
  • line 45: Possible hardcoded password: ')'
freecad/AIGenFurniture/vendor/reportlab/lib/fontfinder.py3
  • line 61: Consider possible security implications associated with pickle module.
  • line 63: Using quoteattr to parse untrusted XML data is known to be vulnerable to XML attacks. Replace quoteattr with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  • line 255: Try, Except, Continue detected.
freecad/AIGenFurniture/vendor/reportlab/lib/randomtext.py5
  • line 311: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 416: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 418: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 419: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 420: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/AIGenFurniture/vendor/reportlab/lib/rl_accel.py2
  • line 333: Consider possible security implications associated with the subprocess module.
  • line 361: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/reportlab/lib/testutils.py2
  • line 364: Consider possible security implications associated with the subprocess module.
  • line 365: subprocess call - check for execution of untrusted input.
freecad/AIGenFurniture/vendor/reportlab/lib/utils.py2
  • line 7: Consider possible security implications associated with pickle module.
  • line 1067: Using escape to parse untrusted XML data is known to be vulnerable to XML attacks. Replace escape with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor/reportlab/platypus/doctemplate.py1
  • line 1399: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/AIGenFurniture/vendor/reportlab/platypus/flowables.py1
  • line 2587: Using escape to parse untrusted XML data is known to be vulnerable to XML attacks. Replace escape with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor/reportlab/platypus/tableofcontents.py1
  • line 61: Using unescape to parse untrusted XML data is known to be vulnerable to XML attacks. Replace unescape with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor/stl/main.py1
  • line 52: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
freecad/AIGenFurniture/vendor/stl/stl.py1
  • line 8: Using ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
freecad/AIGenFurniture/vendor_delete/pymupdf/__init__.py5
  • line 17816: Consider possible security implications associated with the subprocess module.
  • line 17818: Starting a process with a partial executable path
  • line 17818: subprocess call with shell=True seems safe, but may be changed in the future, consider rewriting without shell
  • line 17827: Starting a process with a partial executable path
  • line 17827: subprocess call with shell=True seems safe, but may be changed in the future, consider rewriting without shell
freecad/AIGenFurniture/vendor_delete/pymupdf/utils.py1
  • line 5417: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
package.xml1
  • line 21: Icon file 'Resources/Icons/AIGenFurniture_logo_noBG.svg' is too big (>16kB)
INFO 1
Layout1
  • Uses extension based layout
Authors/Maintainers 1
Bogdan

pcb master

6.2023.1· Printed Circuit Board (PCB) Workbench for FreeCAD

0 / 100

Repository

https://github.com/marmni/FreeCAD-PCB
master · Created: 2016-01-06 · Updated: 7 mo · 280 python files

Statistics

5,662
DL(Yr)
623
DL(Mo)
121
Stars
7
Issues
Manifest
Branch
master
Version
6.2023.1
License
AGPLv3.0
Dependencies 19
  • Internal: Draft
  • Internal: Mesh
  • Internal: PySide
  • Internal: Sketcher
  • Internal: pivy
  • Pip: protobuf
  • Warn: ConfigParser (Not in AddonManager allowed packages)
  • Warn: PyQt4 (Not in AddonManager allowed packages)
  • Warn: Sybase (Not in AddonManager allowed packages)
  • Warn: cdecimal (Not in AddonManager allowed packages)
  • Warn: cx_Oracle (Not in AddonManager allowed packages)
  • Warn: dataBase (Not in AddonManager allowed packages)
  • Warn: mx (Not in AddonManager allowed packages)
  • Warn: pgdb (Not in AddonManager allowed packages)
  • Warn: pysqlcipher3 (Not in AddonManager allowed packages)
  • Warn: pysqlite (Not in AddonManager allowed packages)
  • Warn: pytest (Not in AddonManager allowed packages)
  • Warn: pytest_xdist (Not in AddonManager allowed packages)
  • Warn: setuptools (Not in AddonManager allowed packages)
Static Analysis 147
HIGH 3
sqlalchemy/util/langhelpers.py1
  • line 31: Use of weak MD5 hash for security. Consider usedforsecurity=False
package.xml1
  • line 7: Missing license file 'LICENSE'
Layout1
  • Invalid __init__.py file in root. Change to Init.py
MEDIUM 86
PCBbrd.py1
  • line 79: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
PCBdataBase.py8
  • line 345: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 346: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 347: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 369: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 833: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 839: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 856: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 864: Use of possibly insecure function - consider using safer ast.literal_eval.
PCBfunctions.py1
  • line 835: Use of possibly insecure function - consider using safer ast.literal_eval.
PCBpartManaging.py8
  • line 144: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 149: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 591: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 652: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 820: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 821: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 892: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 893: Use of possibly insecure function - consider using safer ast.literal_eval.
command/PCBassembly.py1
  • line 454: Use of possibly insecure function - consider using safer ast.literal_eval.
command/PCBassignModel.py3
  • line 448: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 455: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 918: Use of possibly insecure function - consider using safer ast.literal_eval.
command/PCBexport.py2
  • line 146: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 1241: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
command/PCBexportBOM.py1
  • line 364: Use of possibly insecure function - consider using safer ast.literal_eval.
command/PCBexportDrillingMap.py36
  • line 146: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 280: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 281: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 294: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 295: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 303: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 304: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 305: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 319: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 320: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 321: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 473: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 481: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 491: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 503: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 508: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 515: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 535: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 536: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 544: Use of possibly insecure function - consider using safer ast.literal_eval.
  • … 16 more issues
command/PCBexportHoles.py1
  • line 376: Use of possibly insecure function - consider using safer ast.literal_eval.
command/PCBglue.py1
  • line 126: Use of possibly insecure function - consider using safer ast.literal_eval.
command/PCBsections.py3
  • line 141: Use of possibly insecure function - consider using safer ast.literal_eval.
  • line 739: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 749: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
formats/dialogMAIN_FORM.py1
  • line 306: Use of possibly insecure function - consider using safer ast.literal_eval.
formats/eagle.py2
  • line 59: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
  • line 140: Using xml.dom.minidom.parse to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.dom.minidom.parse with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called
sqlalchemy/dialects/firebird/base.py1
  • line 614: Possible SQL injection vector through string-based query construction.
sqlalchemy/dialects/mssql/base.py1
  • line 2405: Possible SQL injection vector through string-based query construction.
sqlalchemy/dialects/mysql/base.py1
  • line 1683: Possible SQL injection vector through string-based query construction.
sqlalchemy/dialects/oracle/base.py1
  • line 1246: Possible SQL injection vector through string-based query construction.
sqlalchemy/dialects/postgresql/base.py7
  • line 1975: Possible SQL injection vector through string-based query construction.
  • line 2883: Possible SQL injection vector through string-based query construction.
  • line 2964: Possible SQL injection vector through string-based query construction.
  • line 3000: Possible SQL injection vector through string-based query construction.
  • line 3238: Possible SQL injection vector through string-based query construction.
  • line 3416: Possible SQL injection vector through string-based query construction.
  • line 3454: Possible SQL injection vector through string-based query construction.
sqlalchemy/dialects/sqlite/base.py6
  • line 1091: Possible SQL injection vector through string-based query construction.
  • line 1638: Possible SQL injection vector through string-based query construction.
  • line 1677: Possible SQL injection vector through string-based query construction.
  • line 1689: Possible SQL injection vector through string-based query construction.
  • line 2150: Possible SQL injection vector through string-based query construction.
  • line 2159: Possible SQL injection vector through string-based query construction.
sqlalchemy/ext/declarative/clsregistry.py1
  • line 326: Use of possibly insecure function - consider using safer ast.literal_eval.
sqlalchemy/orm/instrumentation.py1
  • line 565: Use of exec detected.
sqlalchemy/orm/persistence.py1
  • line 833: Possible SQL injection vector through string-based query construction.
sqlalchemy/sql/selectable.py1
  • line 3253: Possible SQL injection vector through string-based query construction.
sqlalchemy/testing/plugin/pytestplugin.py1
  • line 321: Use of exec detected.
sqlalchemy/testing/suite/test_reflection.py2
  • line 150: Possible SQL injection vector through string-based query construction.
  • line 431: Possible SQL injection vector through string-based query construction.
sqlalchemy/testing/suite/test_sequence.py1
  • line 85: Possible SQL injection vector through string-based query construction.
sqlalchemy/util/_preloaded.py1
  • line 144: Use of possibly insecure function - consider using safer ast.literal_eval.
sqlalchemy/util/compat.py3
  • line 244: Use of exec detected.
  • line 246: Use of exec detected.
  • line 293: Use of exec detected.
sqlalchemy/util/langhelpers.py3
  • line 162: Use of exec detected.
  • line 207: Use of exec detected.
  • line 1455: Use of exec detected.
LOW 43
PCBbrd.py1
  • line 35: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
PCBfunctions.py2
  • line 327: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 330: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
PCBobjects.py3
  • line 868: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 868: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 868: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
PCBtoolBar.py2
  • line 250: Starting a process without a shell.
  • line 832: Try, Except, Continue detected.
command/PCBassembly.py1
  • line 299: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
command/PCBexplode.py2
  • line 518: Try, Except, Continue detected.
  • line 533: Try, Except, Continue detected.
command/PCBexport.py1
  • line 34: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
command/PCBexportDrillingMap.py1
  • line 164: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
command/PCBexportKerkythea.py3
  • line 169: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 172: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
  • line 346: Try, Except, Continue detected.
command/PCBexportPovRay.py1
  • line 72: Try, Except, Continue detected.
command/PCBsections.py1
  • line 37: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
formats/eagle.py1
  • line 30: Using minidom to parse untrusted XML data is known to be vulnerable to XML attacks. Replace minidom with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
formats/fidocadj.py3
  • line 611: Try, Except, Continue detected.
  • line 863: Try, Except, Continue detected.
  • line 1078: Try, Except, Continue detected.
formats/kicad_v3.py1
  • line 855: Try, Except, Continue detected.
formats/librepcb.py1
  • line 600: Try, Except, Continue detected.
formats/razen.py1
  • line 78: Try, Except, Continue detected.
sqlalchemy/dialects/mssql/base.py3
  • line 2261: Possible hardcoded password: '['
  • line 2264: Possible hardcoded password: ']'
  • line 2266: Possible hardcoded password: '.'
sqlalchemy/dialects/mysql/mysqldb.py1
  • line 184: Possible hardcoded password: 'passwd'
sqlalchemy/dialects/mysql/oursql.py1
  • line 204: Possible hardcoded password: 'passwd'
sqlalchemy/dialects/oracle/cx_oracle.py1
  • line 1176: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
sqlalchemy/dialects/oracle/provision.py1
  • line 101: Possible hardcoded password: 'xe'
sqlalchemy/dialects/sybase/pysybase.py1
  • line 74: Possible hardcoded password: 'passwd'
sqlalchemy/engine/default.py1
  • line 578: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
sqlalchemy/orm/path_registry.py2
  • line 27: Possible hardcoded password: '*'
  • line 28: Possible hardcoded password: '_sa_default'
sqlalchemy/testing/util.py3
  • line 54: Consider possible security implications associated with cPickle module.
  • line 60: Consider possible security implications associated with pickle module.
  • line 87: Standard pseudo-random generators are not suitable for security/cryptographic purposes.
sqlalchemy/util/compat.py3
  • line 108: Consider possible security implications associated with pickle module.
  • line 218: Consider possible security implications associated with cPickle module.
  • line 220: Consider possible security implications associated with pickle module.
license.*1
  • File not found.
INFO 2
package.xml1
  • Missing author information in package.xml
Layout1
  • Uses exec based layout
Authors/Maintainers 1
marmni