Know what you’re shipping.
Paste a repository URL and get security issues, exposed secrets and dependency risk back — each one anchored to a file and a line, not a score with no explanation. Run it twice and it tells you what changed.
Static analysis
Rules for JavaScript, TypeScript and Python, with every finding anchored to a file and a line number you can open.
Secret scanning
Committed keys, tokens and credentials — including ones already rewritten out of HEAD but still reachable in history.
Dependency risk
Known advisories against your lockfile, and on a second run, exactly what is new, resolved or reopened since last time.
No signup to run one. Sign in with GitHub only to reach private repositories.