Maybe the script can have a mode for scanning a framework VS an app, because for many of the properties and functions of a framework class whose access modifiers are public, the script is reporting false positive since those properties and functions are most likely not referenced inside the framework.