↓ Scan your own repo to get a full report
↓Six-layer repo scanner
Paste any public GitHub URL. Security, dependency, IaC, licence, quality and governance checks run in parallel. No account needed.
Pro scan runs Semgrep, Bandit, pip-audit, Checkov and detect-secrets — deeper coverage, stored results, 30-day history.
20 runs/month from $20 · credits never expire
Pro scan uses your tbo- API key. Results are stored for 30 days.
Health Score
Severity Distribution
Layer Scores
Scanner runs on AWS Lambda · Free tier · Read the methodology
How it works
Six analysis layers run in parallel on AWS Lambda — no containers, no VMs. The scanner inspects your public GitHub repo without cloning it.
🔐 Security
Checks for hardcoded secrets, insecure defaults, and SAST patterns across your source files.
📦 Dependencies
Detects known CVEs in your dependency manifest using OSV and advisory databases.
🏗️ IaC
Scans Terraform, CloudFormation, and Kubernetes manifests for security misconfigurations.
📄 Licence
Flags GPL, AGPL, and licence-absent packages that could block commercial use.
✨ Code quality
Highlights missing tests, coverage gaps, and CI configuration issues.
🏛️ Governance
Checks for SECURITY.md, CODEOWNERS, branch protection, and release hygiene.