THE MILESTONE

We just scanned our one billionth line of code.

 

We did it — one billion lines of code scanned. Our AI-powered code intelligence platform recently passed the 1,000,000,000-line milestone, and we’re equal parts excited and amazed. If those lines were printed out and laid end-to-end, they’d stretch over 15,000 miles — more than halfway around the Earth.

Beyond the fun statistics, this milestone gives us a treasure trove of data about the state of modern code. Along the way, our AI assistant Ada generated more than 23,000 insights — spotting bugs, suggesting performance improvements, and flagging things like a suspicious hard-coded credential. Many echo exactly what a human reviewer would say, just scaled to billions of lines.

 

1B+

Lines Scanned

23K+

AI Insights

1M+

Quality Issues

165K+

Vulnerabilities

62K

Dependencies

3,400+

File Types

CODE QUALITY AT SCALE

Over a million code quality issues — and counting.

Scanning a billion lines of code, you’re bound to find some warts. Our platform uncovered over 1,000,000 code quality issues spread across countless projects. The silver lining: they’re no longer lurking unbeknownst to developers. Here are the most common offenders our analysis flagged:

01

Outdated dependencies

Libraries stuck on old versions, missing important fixes.

02

Code duplication

The same logic copy-pasted across a project, multiplying maintenance risk.

03

Insecure URLs

Plain http:// endpoints where https:// was available.

04

Tangled logic

Deeply nested conditionals that are hard to read and harder to test.

These patterns are widespread — not a sign your project is uniquely behind.

Many teams struggle with the same things: keeping dependencies current, avoiding duplicate code, using secure practices, and managing complexity. These are fundamentally solvable problems — routine dependency updates, linters that catch insecure links, and refactoring gnarly functions can drastically cut that count down.

 
THE SECURITY PICTURE

165,000+ security vulnerabilities, hiding in plain sight.

We detected over 165,000 security vulnerabilities across the codebases we analyzed — roughly 53,000 high severity and 107,000 medium, with the remainder lower priority. Things like SQL injection flaws, risky system commands, hard-coded secrets, and buffer overflows.

 

That number tracks with the wider industry — most software has at least a few skeletons in the closet. Many vulnerabilities trace back to the same outdated dependencies driving our quality-issue count, or to complex code where a subtle security issue slipped in unnoticed.

 

Secure code and clean code go hand-in-hand.

When you keep your code simple and your libraries updated, you also reduce the chances of a severe vulnerability slipping through.

 

THE OPEN-SOURCE REALITY

62,000 dependencies, from nearly 4,000 vendors.

A billion lines of code isn’t written from scratch. We identified over 62,000 open-source dependencies in use, from nearly 4,000 unique maintainers and ecosystems — npm, PyPI, Packagist, Maven, and more. Modern software really is standing on the shoulders of open-source giants.

 

But every one of those 62,000 components is also a piece of someone else’s code that could need an update or carry a bug. We flagged over 37,500 components as outdated, and roughly 30,000 of those carried a software licence — meaning security risk and licensing risk often travel together.

 

WHAT THE CODE ITSELF LOOKS LIKE

JavaScript’s the most complex, PHP’s the most common, and we scanned 3,400+ file types.

JavaScript files showed the highest complexity scores on average — less because JS developers write wilder logic, and more because minified files (all the code smooshed onto one line) skew the metric. PHP came a close second, often from long-lived projects that accreted features over years.

Language-wise, PHP topped the list, with JavaScript a close second — reflecting how much of the web still runs on both. Source code was only part of the picture: we encountered more than 3,400 distinct file types, from JSON and YAML configs to shell scripts and the occasional COBOL copybook.

 

WHY THIS MATTERS

What a billion lines taught us about modern software.

Nearly every codebase has room for improvement

A million-plus issues and 165k vulnerabilities sound discouraging, but it’s actually useful knowledge — it’s normal for software to have imperfections. The important part is building a habit of finding and fixing them before they pile up.

 

01

Security and code quality are interconnected

Many vulnerabilities come from known, well-understood issues — a library with a CVE, a misconfiguration. Investing in code quality inherently bolsters security, and letting quality slip usually means security holes follow.

 

02

Managing open source at scale is a business necessity

With tens of thousands of components in play, teams need a real strategy: inventorying dependencies, tracking vulnerability feeds, and staying on top of license compliance — not hoping nobody asks.

 

03

Technical debt is measurable, not just a feeling

Outdated libraries, complex functions, a million minor issues — these are all forms of technical debt you can quantify, which makes it possible to prioritize instead of guessing.

 

04

Legacy code and languages stick around

PHP topping the language count and 3,400+ file types tell the same story: old technology rarely disappears, it becomes legacy you still have to maintain alongside anything new.

 

05

Legacy code and languages stick around

No one scans a billion lines by hand. AI and automation handle the grunt work of scanning and triage, so developers can focus on judgment calls — as long as the output stays accessible, not overwhelming.

 

06

Duplication and complexity point to a need for refactoring cycles

Teams that build fast tend to accumulate copy-paste code and tangled logic. The organisations that stay healthy long-term schedule time to pay that debt down, rather than letting it compound.

 

07

FROM COMPLEXITY TO CLARITY

Move from uncertainty to complete code confidence.

Get the independent intelligence you need to understand, verify and protect your software.

Book a demo