A repository audit checks your website or app's source code for problems, such as out-of-date dependencies, known security advisories, insecure configuration and maintainability issues, plus extra checks for the platform you use. You add the repository under **Diagnose → Repositories**, run an audit whenever you like or on a schedule, and get a score, a list of findings and a picture of the technology in the project.

To audit a whole site, including its servers, domains and live pages, see [Audits, targets and health reports](/assure-and-diagnose/audits-and-findings).

## Before you start

- Audits must be included in your package. See [Package and add-ons](/account-and-access/package-and-add-ons).
- You need permission to view repositories and audits, and separate permission to add repositories and start audits. See [Users, teams, groups and permissions](/account-and-access/users-teams-groups-and-permissions).
- For a private repository, you need a **GitHub**, **GitLab**, **Bitbucket** or **Custom Git Repository** connection. You can create one while adding the repository. See [Connecting a provider](/connections/connecting-a-provider).

## Adding a repository

1. Go to **Diagnose → Repositories**.
2. Under **Add repository**, choose a **Connection** to your Git provider. If you don't have one yet, select **Add connection** to create it in a new window.
3. Leave **Repository URL** empty to use the connection's repository. Each connection covers one repository, and a different repository's URL is refused. For a public repository without a connection, enter its URL instead, such as `https://github.com/organisation/repository`.
4. Optionally, enter the **Default branch** to audit.
5. Select **Add repository**. You'll see "Repository added."

The repository appears in the list with its connection, **Provider**, **Default branch** and **Detected version**. Select **View** to open it, or **Remove** and confirm to remove it.

When you add a repository, Structurell also creates an audit target of the same name, with the repository as one of its parts. You can add servers and domains to that target later. See [Audits, targets and health reports](/assure-and-diagnose/audits-and-findings).

## Choosing checks and scheduling audits

Open the repository with **View**. The **Audit schedule** panel decides what every audit of this repository checks, whether you start it yourself or it runs on a schedule, so set it up before your first audit.

1. Choose every **Check groups** option that applies to the project: **Adobe Commerce**, **Magento Open Source**, **PHP**, **PHP web**, **JavaScript**, **Laravel**, **WordPress**, **Next.js** or **React**. At least one is required.
2. Optionally, choose the live site's **Domain** from your subscription's domains, so the audit can include checks against the live site. Domains are added under **Account → Domains**. See [Domains](/account-and-access/domains).
3. To audit automatically, switch on **Enabled**, then choose **Daily**, **Weekly** or **Monthly** under **Audit schedule** (each runs at 22:00), or **Advanced** to build your own timing.
4. Choose the **Timezone** the schedule follows.
5. Select **Save**. You'll see "Audit schedule saved."

When the schedule is on, the panel shows when the **Next audit** will run. If a scheduled audit couldn't start, the reason is shown in the panel. Select **Cancel** to undo changes you haven't saved.

The schedule also appears on **Assure → Schedules** as **Repository schedule**, where you can select **Run now**. Scheduled repository audits send an alert for every finished run. See [Assurance reviews and audit schedules](/assure-and-diagnose/assurance-reviews-and-schedules).

## Running an audit

1. Open the repository.
2. Select **Start audit**.

Structurell takes a copy of the repository's code and runs the checks in the background. The audit's page opens straight away and updates live as each step completes. When it finishes, you get an **Audit Results** notification, and so do your subscription administrators.

Every audit of the repository is listed below the schedule panel, with tiles for **Runs**, **Failed**, **Avg score** and **Last run**. **Diagnose → Audits** lists audits from all your repositories and targets. An audit's status is **Pending**, **In Progress**, **Completed**, **Failed**, **Skipped** or **Blocked**.

## Reading the results

Select **View** on an audit to open it. The **Audit Run** summary shows its status, current **Step**, **Elapsed** time, **Started At**, **Finished At** and **Progress**. The results are split into tabs:

- **Outcome**: the overall **Score**, findings **By Severity** and **By Status**, a **Recommendation** and the **Priority Findings** to look at first. If the audit failed, the **Failure Reason** is shown here.
- **Steps**: each step with its status, start and finish times, **Step Duration** and any **Message**.
- **Details**: a log of what happened during the audit.
- **Findings**: every finding with its severity, description and recommendation. Change a finding's status in the **Status** list, or select **View** to open it. Passed checks can't be changed.
- **Technology**: the **Platform**, **Platform Version** and **Framework Versions** detected, and the modules, **Plugins** and **Themes** found, with their required and installed versions.

Only a completed audit's score counts towards **Avg score**. A failed audit isn't a result.

Findings from every audit are gathered under **Diagnose → Findings**. See [Managing findings](/assure-and-diagnose/managing-findings).

## Troubleshooting

- **The URL is refused when adding a repository.** With a connection chosen, leave **Repository URL** empty or use that connection's own repository. Without a connection, Structurell can only fetch repositories it can reach publicly, so add a connection for private ones.
- **The audit failed.** Open it and check the **Failure Reason** on the **Outcome** tab and the messages on the **Steps** tab. A common cause is that the repository couldn't be downloaded. Check the connection on **Account → Connections**, then select **Start audit** again. See [Troubleshooting connections](/connections/troubleshooting-connections).
- **Checks I expected didn't run.** Make sure you've chosen the right **Check groups** and selected **Save** before starting the audit.
- **Save is greyed out.** Nothing has changed since the last save, or no **Check groups** option is selected.