Flat price per team · hosted in the EU · no AI · free for public repos
Stop leaked keys and days-old packages before they merge.
One security check on every pull request, at a flat price for the whole team.
Your code is read on one server in Finland and never sent to an AI model or any
third party — only package names and versions go out, to the package registries and
their download counters.
The check fails when it finds something serious, so it blocks the merge as soon as you
mark it as required. The first report lands about a minute after you install, on the code
already in your repository.
Before you trust any of that:
we publish how often we are wrong →
83 corrections, each one from a line we got wrong in a real public repository.
We start with the code that is already there, because the mistake we find most often is
never added in a pull request at all. After that, every dependency you add gets checked
for how old it is and whether anyone actually uses it — the profile of a package an
attacker registered last week, which installs without a word and has no advisory yet.
Plus hardcoded credentials, SQL built by interpolation, insecure deserialization and
model output rendered as raw HTML. Findings land as a comment on the pull request, with
the file, the line and the fix.
Here is the measurement that made us build it that way. We looked for one specific
mistake — a service key carrying a NEXT_PUBLIC_ or VITE_
prefix, which the framework ships to every visitor's browser — in 63 real pull requests
from Next.js and Vite projects. It appeared zero times. In the existing code of 8
real repositories it appeared in seven. It gets written once, the day the project
is created, and a tool that only reads diffs will never see it.
We audit public pull requests every day to keep ourselves honest. In more than 1,400
dependencies added by real developers we found no invented packages — the attack
everyone writes about is rarer than the headlines suggest, and we would rather tell you
that than sell you a scare. What we do find, on about one pull request in fifteen, is
credentials and injection. Read the measurement, or see the live count.
Built for European software teams and agencies of five to twenty developers shipping
React/Next.js and Python with Copilot, Cursor or Claude — and for the lead who has to tell
a client where their code goes. Where your code goes →