Scanverra
Repo Scanner

Your codebase health,
at a glance

Connect GitHub or Bitbucket and scan any repo for SAST issues across JS, TS, and Python, hardcoded secrets, dependency CVEs with outdated detection, and IaC misconfigurations - with AI-written fixes and one-click PR creation.

Scan your repo free

What we analyze

Dependencies, vulnerabilities, and code quality - all in one pass.

SAST & secrets detection

Static analysis for JS, TS, and Python - covering SSRF, NoSQL injection, open redirect, template injection, sandbox escapes, insecure deserialization, and secret patterns including entropy-based detection.

Dependency CVE scanning

npm, yarn, and pnpm lockfiles checked against the npm advisory database. CVEs graded by severity with fix versions, plus outdated package detection showing the latest available version.

IaC & config security

Dockerfile, docker-compose, Kubernetes (security contexts, capabilities, ConfigMap secrets), and GitHub Actions - pinned actions, write-all permissions, and script injection all checked.

AI fixes & PR creation

Every finding comes with an AI-written fix. Select the ones you want and Scanverra opens a pull request on GitHub - title, body, and diff pre-filled. Suppress false positives with inline comments.

How it works

From scan to merged PR - without leaving the browser.

Connect GitHub or Bitbucket

OAuth in one click - we request only the permissions needed to read your code and optionally open pull requests on GitHub.

Select a repo and branch

Choose any repo from the list. Pick the branch to scan - defaults to your repo's default branch.

Review findings by category

Security, Quality, IaC, Dependencies, and Analysis tabs break down every finding with severity, file path, and line number.

Apply fixes and create a PR

Accept AI-suggested fixes, tweak the code if needed, then open a pull request on GitHub with one click.

Full check list

Comprehensive signals across SAST, secrets, dependencies, IaC, and code quality.

JS/TS SAST - XSS, injection, SSRF, open redirect, ReDoS
Python SAST - eval, pickle, SQL injection, subprocess, yaml.load
NoSQL injection & template injection detection
vm sandbox escape & insecure deserialization
Secret patterns including entropy-based detection
AWS, GitHub, Stripe, OpenAI, Anthropic, GCP, Cloudflare key detection
npm, yarn, and pnpm dependency CVE scanning
Critical / High / Medium / Low severity grading
Outdated package detection with latest version comparison
Direct dependency list with per-package security status
Dockerfile, docker-compose, Kubernetes, GitHub Actions IaC rules
Kubernetes security context checks (runAsNonRoot, allowPrivilegeEscalation)
Kubernetes ConfigMap secret detection & capability auditing
GitHub Actions: pinned actions, write-all permissions, script injection
Code quality - cyclomatic complexity, function length, file size
TypeScript 'any' usage & empty catch block detection
Code duplication & technical debt markers
Security score with quality gate (Pass/Fail)
Inline suppression via // scanverra-ignore or # nosec
GitHub & Bitbucket repository support
AI-generated code fixes with line-level context
One-click GitHub PR creation

Scan, fix, and ship - in minutes

Free. Review every change before it lands. PR created only when you say so.