← All agents

Code Security Scan

Scans a snippet for hardcoded secrets, injection-prone patterns and unsafe APIs, with a concrete fix for each finding.

Free run returns your 3 most severe findings. No signup, no card.

Your code is analysed in memory and never stored, logged, or sent to a model provider. Don't paste live production secrets — if a key appears in a finding, rotate it.

What it looks for

  • Hardcoded secrets — API keys, tokens, private keys, connection strings
  • Injection risk — string-built SQL, shell and HTML sinks
  • Unsafe APIs — eval, deserialisation, disabled TLS verification
  • Weak crypto and insecure randomness for security-sensitive values

These are pattern checks over the text you paste, not a compiler or a taint analysis. They catch the mistakes that recur in review — they cannot prove the absence of a vulnerability, and a clean result is not a security audit. For that, talk to us.