Find out what you shipped
Every plan runs the same scanners — logic flaws, dependency vulnerabilities, access-rule and authorization flaws, and leaked credentials — and tells you in plain language what someone could do with each one, with a fix prompt for your own editor and a verdict on whether it should stop your launch. Repositories are unlimited on every plan. What you pay for is Security Checks — paid checks come with Shield's own AI Review of what it found, bundled in up to your plan's allowance, nothing extra to buy.
Pay as you go
$0 USD
No card, no subscription.
Your first Security Check per repository, on us — see what it finds before you pay for another.
1 free Security Check per repository Unlimited repositories Plain-language findings and a ship / don't-ship verdict
Buy checks any time, no subscription
- Scan Pack $5 USD
- Fix Pack best value$9 USD
Recommended
Pro
$19 USD / month
Billed monthly, cancel any time.
For anyone shipping often enough that a subscription is cheaper.
20 Security Checks a month AI Review bundled in on your first 10 checks each month Unlimited repositories
Run out before renewal?
- Pro top-up $5 USD
Coming soon
Team
For an organisation with a repository past what an individual plan can fully scan — no file-count limit on code scans, secret scans across full git history, and seats and roles for a team instead of a single account. Not available yet — the rest of this page is what you can actually buy today.
What every plan looks at
The depth does not change with what you pay — every Security Check on every plan runs the same scanners. Every paid check comes with AI Review bundled in, up to your plan's AI Review allowance — the free first check doesn't get one at all. What changes with price is volume: how many checks you get per dollar, and whether you renew monthly or buy one-off.
Credentials committed to the repo, or anywhere in its history — secret scan Known vulnerabilities in the packages you depend on — dependency scan Injection, unsafe rendering, weak crypto, path traversal, access-rule and authorization flaws — code scan Plain-language explanation, a launch verdict, and a fix prompt for every finding
Credentials it recognises on sight
By format, not by guesswork — in your files and everywhere in your git history, because deleting the file does not un-leak the key.
- AWS
- Stripe
- GitHub
- GitLab
- Google Cloud
- Supabase
- OpenAI
- Anthropic
- Slack
- Twilio
- SendGrid
- Mailgun
- Postmark
- Shopify
- Square
- PayPal
- Heroku
- Vercel
- Netlify
- Cloudflare
- Datadog
- Sentry
- Segment
- Algolia
- Firebase
- MongoDB
- PlanetScale
- Redis
- RabbitMQ
- npm
- PyPI
- Docker Hub
- Atlassian
- Linear
- Notion
- Discord
- Telegram
- HashiCorp Vault
- Okta
- SSH private keys
- PGP private keys
- RSA private keys
- JWT signing secrets
- Database connection strings
…and the rest of the detector set, plus high-entropy strings that match no known format.
Lockfiles it reads
Whatever you built it with. Every pinned version is checked against the vulnerability feed, including the transitive dependencies you never chose.
- package-lock.json
- pnpm-lock.yaml
- yarn.lock
- bun.lockb
- packages.lock.json
- go.sum
- Cargo.lock
- poetry.lock
- requirements.txt
- Pipfile.lock
- composer.lock
- Gemfile.lock
- pubspec.lock
- Podfile.lock
- gradle.lockfile
- pom.xml
- Dockerfile
- docker-compose.yml
Code flaws it has rules for
Individual rules, not headings — each one a specific pattern, in a specific language. Every Security Check runs all of them, on every plan.
Injection
142 rules
Weak or misused cryptography
61 rules
Exposed secrets and sensitive data
58 rules
Broken access control
57 rules
Memory safety
49 rules
Insecure configuration
48 rules
Unsafe failure handling
29 rules
Authentication and session flaws
21 rules
Insecure design
19 rules
Integrity failures
14 rules
Unsafe deserialization
8 rules
Known-vulnerable components
6 rules
A rule can belong to more than one of these, so adding the counts up would count some of them twice. Each figure is what it says it is; the column is not a total.
When you need more
Human review
Thirty minutes with an engineer, for the finding no prompt can close. Some problems are architectural and no amount of pasting fixes them; we will tell you when yours is one.
$150 USD
What this does not do
A clean report means nothing blocking was found, by these tools, on that commit. It is not a guarantee and we will never word it as one. Nothing you scan is built, installed or executed — the scanners read files, which is why a repository full of untrusted code is safe to point us at.
A paid Security Check's AI Review runs automatically once the scan finishes, whenever your plan bundles one in — nothing to ask for, nothing billed separately — and it produces no findings of its own. It reads the findings your Security Check already returned and adds false-positive analysis, risk order and a fix prompt on top of them. The free first check has no review bundled at all; how many of your paid checks get one depends on your plan — see above.
Bought something you have not used yet? Unused Security Checks and AI Reviews are refundable within 14 days of paying for them — see the refund terms for exactly what that covers.