Scan
An automated sample, clearly labelled
Paste a public GitHub repository URL. A capped set of its files is read through GitHub's public API and a model looks for the three things a security review starts with. It is a sample of a first pass, not a review, and it is worth reading the two lists below before you run it rather than after.
What it does
- Reads a capped number of source and configuration files from a public GitHub repository, through GitHub's documented REST API.
- Looks for the same three things a review starts with: authentication and session handling, access control, and secrets committed to the repository or shipped to the browser.
- Returns grouped observations in plain text, naming the file each one came from where it can name one.
- Says which parts of the repository it did not get to.
What it does not do
- It does not run your code, sign in to anything, or touch a running system. It reads files and nothing else.
- It reads a capped sample, not the repository. On anything large it sees a fraction, and it cannot tell you which fraction mattered.
- It is a language model reading text. It will miss real problems, and it will call things problems that are not. Nothing it returns is a finding until a person has checked it.
- It cannot see private repositories, and it does not ask you for a token so it can try.
- It is not a report. Nothing from this page is scoped, authorised, signed or published.
Before you paste a URL
Scan repositories you own, or that you have permission to scan. That rule is not different here because the reading is automated — it is the same rule every report on this site states at the top of itself.
The URL is sent to this site's API, which reads the repository from GitHub. Only public repositories are readable, so pasting one exposes nothing that was not already public. Answers are cached for a while, so running the same repository twice may return the stored answer rather than a fresh read.
Run it
This part needs JavaScript: it posts the URL to the API and renders the reply. Nothing else on this page needs it, and neither does any report in the archive.
What a review from me adds that this cannot
This is the honest end of the automated part. Everything below is the part a person does, and none of it is something the run above can be improved into.
- It reads the whole codebase, and it reads it knowing what the application is for. Access control is the clearest case: whether one user reaching another user's row is a bug or the intended behaviour is a question about your product, not about your code. A pass with no idea what the app does cannot answer it, and this one does not pretend to.
- It separates what is exploitable from what merely looks wrong. A long list of things that pattern-match to danger is a to-do list you did not ask for. The work is deciding which of them a stranger can actually reach.
- Scope and authorisation are agreed in writing first. Which repositories and environments are in, which are out, and confirmation from whoever owns the code that they want it reviewed.
- Each finding comes with the fix, written against your branch as a patch or a pull request, with a note on what it changes and why.
- It states what it did not cover. Every report ends with the honest boundary of the review, so you know what you are not allowed to assume was checked.
What a security review coversWhy this endpoint is an SSRF by design
