Coverage · Code Security
Code Security coverage, from source to findings.
14 code languages, 32 configuration and template families, and 8 review areas. This is the current source inventory. Check your installed CLI, verified rule bundle and per-scan analysis coverage to see what ran.
- 14
- Languages
- 32
- Configuration / template families
- 8
- Review surfaces
- All
- Surfaces in every plan
What gets examined
8 review areas, with explicit scan scope.
Select the checks you need. Dependency review requires an advisory snapshot. AI inventory and malicious-package review use separate commands; scan --full does not run every listed area.
SAST
Source-code review
Selected injection, traversal, deserialization, cryptography, authentication and business-logic patterns. Findings carry CWE references, confidence and analysis limits; missing-control candidates require contextual review.
SCA
Dependency review
Recognised direct and transitive components matched locally against the supplied advisory snapshot. Results depend on supported manifests, available versions and the age of that snapshot.
Malicious
Malicious package detection
The audit command checks recognised dependencies with typosquatting heuristics; --malicious <file> adds a supplied known-malicious list. These checks are separate from scan --full and do not prove a package is malicious or safe.
SBOM
Software inventory
CycloneDX 1.5 and SPDX 2.3 exports that state their own scope, so a source inventory is never mistaken for a built-artifact one.
CBOM
Cryptographic inventory
Recognised cryptographic usage, including currently acceptable algorithms, classified by kind and quantum-migration relevance. Unrecognised wrappers and runtime-only usage may be absent.
AIBOM
AI inventory
The aibom command recognises selected AI SDK and model patterns in supported source and dependency files. Risk labels describe likely provider usage; they do not prove runtime data transfer, exact model versions or complete AI coverage.
Credentials
Secrets review
Selected credentials and sensitive values in code and configuration. The secret scanner reports redacted previews and hashes; its upload records omit secret values. This does not guarantee that opted-in source snippets are free of sensitive data.
IaC
Configuration review
Infrastructure, container and pipeline configuration, where a single permissive setting undoes the code review above it.
Source inventory
Counted from the rule and engine sources.
These counts are generated from the repositories, not estimates. They count definitions and catalogue entries, not confirmed vulnerabilities, independent vulnerability classes, or the contents of every deployed bundle. Fixture results and release validation are separate evidence.
- 2,107
- Rule definitions in source
- 221
- Distinct CWE references in rule metadata
- 56
- Credential detector definitions
- 65
- Cryptographic catalogue entries
372 rules use data-flow matching; other rules use syntax, text, missing-control or ordered-event matching. 622 source rules carry low confidence. REVIEW candidates need contextual verification, not automatic treatment as confirmed vulnerabilities.
Provider-side reset invalidation, MFA policy, distributed rate limits, database concurrency and browser history restoration require integration or runtime evidence. No rule count or clean scan proves that every vulnerability has been checked.
Exports
Results move into the tools you already use. Nothing here is a premium format.
SARIF 2.1.0
Code and configuration findings, with available data-flow evidence and analysis coverage.
CycloneDX 1.5
Software inventory, stating the scope it was built from.
SPDX 2.3
Software inventory in the second standard format.
CycloneDX VEX
One entry per advisory, listing every component it affects.
CycloneDX 1.6 CBOM
Cryptographic inventory, with quantum-vulnerable algorithms marked.
CycloneDX 1.6 ML-BOM
AI and ML component inventory: SDKs, model APIs and local models with risk classification.
HTML
Self-contained offline report. Open in any browser without a network connection.
CSV
Spreadsheet-ready findings export with BOM header and formula-injection protection.
XML
Machine-readable findings document for ingestion by other tooling.
JSON
Structured customer-facing findings and coverage. Private rule metadata is omitted; this is not the authenticated upload body.
Depth of analysis
Three analysis capabilities, with limits.
L1 describes the separate inventory/dependency surface. A table row shows L3 when that family has data-flow rules, otherwise L2. These labels are capabilities, not completeness or assurance grades.
L1
Inventory and dependencies
Recognised components matched against available advisories, with software and cryptographic inventories you can export.
Supported lockfiles and manifests identify components for offline advisory matching when a vulnerability database is supplied. A source inventory is not a complete built-artifact inventory; an advisory match does not prove reachable exploitation.
L2
Direct code analysis
Unsafe API use, weak cryptography, disabled protections, hardcoded credentials and insecure configuration, found in the code itself.
Depending on the rule, checks use parsed syntax, selected text, missing recognised controls or source-ordered events. Findings carry locations, confidence and limits. Missing-control and race candidates require contextual review.
L3
Data-flow analysis
Injection and traversal flaws traced from the point untrusted input enters to the point it reaches a dangerous operation.
The analysis follows modelled inputs within functions and at module level, and through named functions in the same repository, including functions in other files, up to a few calls deep within a time budget. Sanitizers are recognised by configured patterns, not proved correct. Dynamic dispatch, reflection, deep or recursive call chains and runtime state are not resolved. A language having L3 rules does not mean every framework or vulnerability has data-flow coverage.
Languages
14 with data-flow analysis, 14 in total.
Every language here is part of the same product and the same plan. Coverage for your stack is confirmed in writing during scoping.
| Language | Depth | Selected patterns; not exhaustive |
|---|---|---|
| Python | L3 | Selected web input, ORM, serialization and cryptography patterns |
| Java | L3 | Selected Spring, JDBC, serialization and concurrency patterns |
| JavaScript | L3 | Selected Node/Express input, account routes, quota and cache patterns |
| Go | L3 | Selected standard-library, HTTP, SQL and session-lifecycle patterns |
| PHP | L3 | Selected Laravel, PDO, input handling and session patterns |
| C# | L3 | Selected ASP.NET, SQL, serialization and token-validation patterns |
| TypeScript | L3 | Selected server/browser input, account routes, quota and cache patterns |
| C | L3 | Selected memory, filesystem, integer and thread-safety patterns |
| C++ | L3 | Selected memory, filesystem, casts and concurrency patterns |
| Kotlin | L3 | Selected input, cryptography and Spring token/cache patterns |
| Ruby | L3 | Selected Rails/Devise, input, quota and shared-cache patterns |
| Swift | L3 | Selected input, transport, local storage and filesystem patterns |
| Rust | L3 | Selected unsafe code, input, process and filesystem patterns |
| Scala | L3 | Selected input, query construction, cryptography and NIO patterns |
Configuration and template families
Each configuration and template family has its own row, including related framework configuration. Repository settings do not establish the effective configuration of a running deployment.
| Format | Depth | Focus |
|---|---|---|
| Terraform | L2 | Selected cloud resources, policy and API Gateway throttling settings |
| Kubernetes | L2 | Selected workload, RBAC and resource settings |
| Dockerfile | L2 | Selected image, package, user and build settings |
| Docker Compose | L2 | Selected capability, confinement, namespace, socket and port settings |
| GitHub Actions | L2 | Selected workflow triggers, action pinning and script inputs |
| Dependency manifests | L2 | Selected integrity, pinning, registry and declared-license settings |
| Desktop configuration | L2 | Selected MSBuild, CMake, Xcode, entitlement and execution-manifest settings; no binary verification |
| Ansible | L2 | Selected tasks, file modes, checksums and credential settings |
| nginx | L2 | Selected TLS, header, request and dry-run limit directives |
| HTTP headers | L2 | Selected header declarations in supported server configuration files |
| Android manifest | L2 | Selected exported-component, backup and transport settings |
| CI pipelines | L2 | Selected image, command and credential patterns |
| CloudFormation | L2 | Selected resource, storage and policy declarations |
| Bicep | L2 | Selected storage, Key Vault, TLS, firewall and secure-parameter settings |
| OpenAPI | L2 | Selected operation, authentication and schema declarations |
| Pulumi | L2 | Selected secret, resource and access-policy patterns |
| SQL | L2 | Selected statements, procedures, definers and grants |
| SSH configuration | L2 | Selected authentication, key-exchange and daemon settings |
| Crossplane | L2 | Selected connection-secret and managed-resource declarations |
| Serverless Framework | L2 | Selected function role, environment and endpoint authoriser settings |
| HTML | L2 | Selected script, resource and form markup |
| Shell scripts | L2 | Selected eval, download-and-run, temporary file, TLS and permission patterns |
| PowerShell | L2 | Selected Invoke-Expression, download-and-run, execution policy and TLS patterns |
| iOS property list | L2 | Selected transport, sharing and application settings |
| Jenkins | L2 | Selected pipeline, command and credential patterns |
| Maven | L2 | Selected repository and dependency declarations |
| Spring properties | L2 | Selected password and TLS properties |
| ASP.NET configuration | L2 | Selected credential, cookie, debug and directory-browsing settings |
| PHP configuration | L2 | Selected session and runtime settings |
| Java templates | L2 | Selected JSP and Thymeleaf output patterns |
| PHP templates | L2 | Selected Twig and Blade output patterns |
| JavaScript templates | L2 | Selected template output patterns |
Every plan
Every surface is included.
No per-language pricing, no separate SAST, dependency, secrets or infrastructure products, no charge per scan and no premium export format. Every plan scans every surface; Business adds organisation features such as risk management and the software inventory; Enterprise adds single sign-on.
As scanning coverage grows, every plan receives the additions.
See pricingA useful next conversation
Find the right product for your review workflow.
Tell us what you need to examine, where your work runs, and what evidence your team needs.