Scan a repository

Find out what you shipped

Every plan runs the same scanners — logic flaws, dependency vulnerabilities, access-rule and authorization flaws, and leaked credentials — and tells you in plain language what someone could do with each one, with a fix prompt for your own editor and a verdict on whether it should stop your launch. Repositories are unlimited on every plan. What you pay for is Security Checks — paid checks come with Shield's own AI Review of what it found, bundled in up to your plan's allowance, nothing extra to buy.

Pay as you go

$0 USD

No card, no subscription.

Your first Security Check per repository, on us — see what it finds before you pay for another.

  • 1 free Security Check per repository
  • Unlimited repositories
  • Plain-language findings and a ship / don't-ship verdict
Start free

Buy checks any time, no subscription

  • Scan Pack 1 check, AI Review included$5 USD
  • Fix Pack best value3 checks, AI Review on every one$9 USD

Recommended

Pro

$19 USD / month

Billed monthly, cancel any time.

For anyone shipping often enough that a subscription is cheaper.

  • 20 Security Checks a month
  • AI Review bundled in on your first 10 checks each month
  • Unlimited repositories
Start free, upgrade later

Run out before renewal?

  • Pro top-up 2 checks, subscriber rate$5 USD

Coming soon

Team

For an organisation with a repository past what an individual plan can fully scan — no file-count limit on code scans, secret scans across full git history, and seats and roles for a team instead of a single account. Not available yet — the rest of this page is what you can actually buy today.

What every plan looks at

The depth does not change with what you pay — every Security Check on every plan runs the same scanners. Every paid check comes with AI Review bundled in, up to your plan's AI Review allowance — the free first check doesn't get one at all. What changes with price is volume: how many checks you get per dollar, and whether you renew monthly or buy one-off.

  • Credentials committed to the repo, or anywhere in its history — secret scan
  • Known vulnerabilities in the packages you depend on — dependency scan
  • Injection, unsafe rendering, weak crypto, path traversal, access-rule and authorization flaws — code scan
  • Plain-language explanation, a launch verdict, and a fix prompt for every finding

Credentials it recognises on sight

By format, not by guesswork — in your files and everywhere in your git history, because deleting the file does not un-leak the key.

  • AWS
  • Stripe
  • GitHub
  • GitLab
  • Google Cloud
  • Supabase
  • OpenAI
  • Anthropic
  • Slack
  • Twilio
  • SendGrid
  • Mailgun
  • Postmark
  • Shopify
  • Square
  • PayPal
  • Heroku
  • Vercel
  • Netlify
  • Cloudflare
  • Datadog
  • Sentry
  • Segment
  • Algolia
  • Firebase
  • MongoDB
  • PlanetScale
  • Redis
  • RabbitMQ
  • npm
  • PyPI
  • Docker Hub
  • Atlassian
  • Linear
  • Notion
  • Discord
  • Telegram
  • HashiCorp Vault
  • Okta
  • SSH private keys
  • PGP private keys
  • RSA private keys
  • JWT signing secrets
  • Database connection strings

…and the rest of the detector set, plus high-entropy strings that match no known format.

Lockfiles it reads

Whatever you built it with. Every pinned version is checked against the vulnerability feed, including the transitive dependencies you never chose.

  • package-lock.json
  • pnpm-lock.yaml
  • yarn.lock
  • bun.lockb
  • packages.lock.json
  • go.sum
  • Cargo.lock
  • poetry.lock
  • requirements.txt
  • Pipfile.lock
  • composer.lock
  • Gemfile.lock
  • pubspec.lock
  • Podfile.lock
  • gradle.lockfile
  • pom.xml
  • Dockerfile
  • docker-compose.yml

Code flaws it has rules for

Individual rules, not headings — each one a specific pattern, in a specific language. Every Security Check runs all of them, on every plan.

  • Injection

    142 rules

  • Weak or misused cryptography

    61 rules

  • Exposed secrets and sensitive data

    58 rules

  • Broken access control

    57 rules

  • Memory safety

    49 rules

  • Insecure configuration

    48 rules

  • Unsafe failure handling

    29 rules

  • Authentication and session flaws

    21 rules

  • Insecure design

    19 rules

  • Integrity failures

    14 rules

  • Unsafe deserialization

    8 rules

  • Known-vulnerable components

    6 rules

A rule can belong to more than one of these, so adding the counts up would count some of them twice. Each figure is what it says it is; the column is not a total.

When you need more

  • Human review

    Thirty minutes with an engineer, for the finding no prompt can close. Some problems are architectural and no amount of pasting fixes them; we will tell you when yours is one.

    $150 USD

What this does not do

A clean report means nothing blocking was found, by these tools, on that commit. It is not a guarantee and we will never word it as one. Nothing you scan is built, installed or executed — the scanners read files, which is why a repository full of untrusted code is safe to point us at.

A paid Security Check's AI Review runs automatically once the scan finishes, whenever your plan bundles one in — nothing to ask for, nothing billed separately — and it produces no findings of its own. It reads the findings your Security Check already returned and adds false-positive analysis, risk order and a fix prompt on top of them. The free first check has no review bundled at all; how many of your paid checks get one depends on your plan — see above.

Bought something you have not used yet? Unused Security Checks and AI Reviews are refundable within 14 days of paying for them — see the refund terms for exactly what that covers.

CodexMotiveShield — an audit for the app you did not entirely write.

© 2026 CodexMotive. Scanning reads your files; it never runs them.

Checking your session…