Skip to content

Know what you’re shipping.

Paste a repository URL and get security issues, exposed secrets and dependency risk back — each one anchored to a file and a line, not a score with no explanation. Run it twice and it tells you what changed.

Static analysis

Rules for JavaScript, TypeScript and Python, with every finding anchored to a file and a line number you can open.

Secret scanning

Committed keys, tokens and credentials — including ones already rewritten out of HEAD but still reachable in history.

Dependency risk

Known advisories against your lockfile, and on a second run, exactly what is new, resolved or reopened since last time.

No signup to run one. Sign in with GitHub only to reach private repositories.