Audit any public repository
Committed secrets, known CVEs, missing CI, unpinned images, Kubernetes and Terraform misconfiguration — 30+ checks and a 0–100 score in about five seconds.
Most viewed
Recently scanned
What the scan looks for
Committed credentials
The whole file tree is scanned with provider-specific patterns — AWS keys, GitHub and GitLab tokens, Stripe keys, private key blocks, database URLs with passwords.
Known vulnerabilities
Every declared dependency is checked against the OSV.dev database, with the CVE identifiers and the packages that need upgrading.
Supply chain in CI
Actions pinned to a moving tag, over-broad workflow permissions, and the pull_request_target pattern that hands repository secrets to untrusted code.
Infrastructure
Terraform state without locking, security groups open to 0.0.0.0/0, unencrypted storage, public buckets, containers running as root.
Private repositories
Connect GitHub or GitLab to audit your private repositories, keep the score history, and get a fix for each finding as a pull request.
Create a free account →