Scan any public GitHub repo
Find exposed secrets, vulnerable dependencies and risky code in about a minute, then share the report with one link.
No sign-up. Public repos only. Try , , .
How it works
- 1
Paste a public repo URL
Any public GitHub repository. No account, no token.
- 2
Get a report in about a minute
An overall risk rating, a health score out of 100 and findings by file.
- 3
Share the link
Every report has its own URL to send to your team or post on LinkedIn.
What the free scan checks
Exposed secrets
API keys, private keys and tokens committed to the code.
Vulnerable dependencies
Known advisories for npm and Python packages from the lockfile.
License risk
Copyleft or unclear licenses in your dependencies.
Code checks
Lint and type errors, risky patterns, complexity and Semgrep rules where available.
Structure
Dead files, duplicated logic and circular imports across the repo.
Tests and team
Test-to-source ratio, CI test steps, and how concentrated the commits are.
Free scan
- ✓ Public GitHub repositories
- ✓ All local checks above
- ✓ Shareable report link
- – No AI review of risky code
- – Secret locations hidden on shared links
With a free account
- ✓ AI review of risky code, with root causes and fixes
- ✓ Private repositories on GitHub and GitLab
- ✓ Automatic pull request reviews
- ✓ Fix with AI and commit back to your branch
We only read public code, never run it, and never store your GitHub credentials for a free scan. Shared reports never show where a secret is or who wrote the code.