Free forever for public repositories

Free code security scanning for open source.

Two public repositories, scanned by the same threat-model-driven engine our paying customers use. No credit card, no trial clock, no sales call. Your code is analysed on our own hardware in Europe.

What the free tier includes

2 public repositories

Any world-readable repo on GitHub. Re-scanning a repo you have already connected never uses another slot.

3 scan credits a month

A credit covers a full Smart scan of a normal repository. Small repos cost one credit; the allowance refreshes every month.

1 dependency audit a month

Your dependency tree checked for known-vulnerable and abandoned packages.

The real engine

Threat-model-driven analysis, not a pattern matcher with a free plan bolted on. Same detection pipeline, smaller model.

European processing

Analysed on our own inference hardware in Europe. Your code is not sent to a US API and is not used to train anything.

Community support

Public issues and discussion. No SLA, and we answer honestly when something is a limitation rather than a bug.

What it does not include

We would rather you knew the edges up front than discovered them mid-scan.

  • Private repositories — the free tier is world-readable repos only
  • Deep scans — Smart scans only, which is the faster and cheaper depth
  • Automated fix pull requests
  • Threat reports and compliance exports

Why we give it away

Open-source maintainers carry a security burden without a security budget, and we benefit from the same ecosystem. It is also how we improve: scanning real code in public finds the gaps in our own detection faster than any internal benchmark, and we publish what we find — including when we get it wrong.

Scan your first repository

Sign in with GitHub, pick a public repo, and you will have findings in minutes.

Start free

Need a consultant-led audit instead? Explore Codelight Audit →