Coverage · Code Security

Code Security coverage, from source to findings.

14 code languages, 32 configuration and template families, and 8 review areas. This is the current source inventory. Check your installed CLI, verified rule bundle and per-scan analysis coverage to see what ran.

14
Languages
32
Configuration / template families
8
Review surfaces
All
Surfaces in every plan

What gets examined

8 review areas, with explicit scan scope.

Select the checks you need. Dependency review requires an advisory snapshot. AI inventory and malicious-package review use separate commands; scan --full does not run every listed area.

SAST

Source-code review

Selected injection, traversal, deserialization, cryptography, authentication and business-logic patterns. Findings carry CWE references, confidence and analysis limits; missing-control candidates require contextual review.

SCA

Dependency review

Recognised direct and transitive components matched locally against the supplied advisory snapshot. Results depend on supported manifests, available versions and the age of that snapshot.

Malicious

Malicious package detection

The audit command checks recognised dependencies with typosquatting heuristics; --malicious <file> adds a supplied known-malicious list. These checks are separate from scan --full and do not prove a package is malicious or safe.

SBOM

Software inventory

CycloneDX 1.5 and SPDX 2.3 exports that state their own scope, so a source inventory is never mistaken for a built-artifact one.

CBOM

Cryptographic inventory

Recognised cryptographic usage, including currently acceptable algorithms, classified by kind and quantum-migration relevance. Unrecognised wrappers and runtime-only usage may be absent.

AIBOM

AI inventory

The aibom command recognises selected AI SDK and model patterns in supported source and dependency files. Risk labels describe likely provider usage; they do not prove runtime data transfer, exact model versions or complete AI coverage.

Credentials

Secrets review

Selected credentials and sensitive values in code and configuration. The secret scanner reports redacted previews and hashes; its upload records omit secret values. This does not guarantee that opted-in source snippets are free of sensitive data.

IaC

Configuration review

Infrastructure, container and pipeline configuration, where a single permissive setting undoes the code review above it.

Source inventory

Counted from the rule and engine sources.

These counts are generated from the repositories, not estimates. They count definitions and catalogue entries, not confirmed vulnerabilities, independent vulnerability classes, or the contents of every deployed bundle. Fixture results and release validation are separate evidence.

2,107
Rule definitions in source
221
Distinct CWE references in rule metadata
56
Credential detector definitions
65
Cryptographic catalogue entries

372 rules use data-flow matching; other rules use syntax, text, missing-control or ordered-event matching. 622 source rules carry low confidence. REVIEW candidates need contextual verification, not automatic treatment as confirmed vulnerabilities.

Provider-side reset invalidation, MFA policy, distributed rate limits, database concurrency and browser history restoration require integration or runtime evidence. No rule count or clean scan proves that every vulnerability has been checked.

Exports

Results move into the tools you already use. Nothing here is a premium format.

SARIF 2.1.0

Code and configuration findings, with available data-flow evidence and analysis coverage.

CycloneDX 1.5

Software inventory, stating the scope it was built from.

SPDX 2.3

Software inventory in the second standard format.

CycloneDX VEX

One entry per advisory, listing every component it affects.

CycloneDX 1.6 CBOM

Cryptographic inventory, with quantum-vulnerable algorithms marked.

CycloneDX 1.6 ML-BOM

AI and ML component inventory: SDKs, model APIs and local models with risk classification.

HTML

Self-contained offline report. Open in any browser without a network connection.

CSV

Spreadsheet-ready findings export with BOM header and formula-injection protection.

XML

Machine-readable findings document for ingestion by other tooling.

JSON

Structured customer-facing findings and coverage. Private rule metadata is omitted; this is not the authenticated upload body.

Depth of analysis

Three analysis capabilities, with limits.

L1 describes the separate inventory/dependency surface. A table row shows L3 when that family has data-flow rules, otherwise L2. These labels are capabilities, not completeness or assurance grades.

L1

Inventory and dependencies

Recognised components matched against available advisories, with software and cryptographic inventories you can export.

Supported lockfiles and manifests identify components for offline advisory matching when a vulnerability database is supplied. A source inventory is not a complete built-artifact inventory; an advisory match does not prove reachable exploitation.

L2

Direct code analysis

Unsafe API use, weak cryptography, disabled protections, hardcoded credentials and insecure configuration, found in the code itself.

Depending on the rule, checks use parsed syntax, selected text, missing recognised controls or source-ordered events. Findings carry locations, confidence and limits. Missing-control and race candidates require contextual review.

L3

Data-flow analysis

Injection and traversal flaws traced from the point untrusted input enters to the point it reaches a dangerous operation.

The analysis follows modelled inputs within functions and at module level, and through named functions in the same repository, including functions in other files, up to a few calls deep within a time budget. Sanitizers are recognised by configured patterns, not proved correct. Dynamic dispatch, reflection, deep or recursive call chains and runtime state are not resolved. A language having L3 rules does not mean every framework or vulnerability has data-flow coverage.

Languages

14 with data-flow analysis, 14 in total.

Every language here is part of the same product and the same plan. Coverage for your stack is confirmed in writing during scoping.

Languages and depth of analysis
LanguageDepthSelected patterns; not exhaustive
PythonL3Selected web input, ORM, serialization and cryptography patterns
JavaL3Selected Spring, JDBC, serialization and concurrency patterns
JavaScriptL3Selected Node/Express input, account routes, quota and cache patterns
GoL3Selected standard-library, HTTP, SQL and session-lifecycle patterns
PHPL3Selected Laravel, PDO, input handling and session patterns
C#L3Selected ASP.NET, SQL, serialization and token-validation patterns
TypeScriptL3Selected server/browser input, account routes, quota and cache patterns
CL3Selected memory, filesystem, integer and thread-safety patterns
C++L3Selected memory, filesystem, casts and concurrency patterns
KotlinL3Selected input, cryptography and Spring token/cache patterns
RubyL3Selected Rails/Devise, input, quota and shared-cache patterns
SwiftL3Selected input, transport, local storage and filesystem patterns
RustL3Selected unsafe code, input, process and filesystem patterns
ScalaL3Selected input, query construction, cryptography and NIO patterns

Configuration and template families

Each configuration and template family has its own row, including related framework configuration. Repository settings do not establish the effective configuration of a running deployment.

Configuration and template rule families
FormatDepthFocus
TerraformL2Selected cloud resources, policy and API Gateway throttling settings
KubernetesL2Selected workload, RBAC and resource settings
DockerfileL2Selected image, package, user and build settings
Docker ComposeL2Selected capability, confinement, namespace, socket and port settings
GitHub ActionsL2Selected workflow triggers, action pinning and script inputs
Dependency manifestsL2Selected integrity, pinning, registry and declared-license settings
Desktop configurationL2Selected MSBuild, CMake, Xcode, entitlement and execution-manifest settings; no binary verification
AnsibleL2Selected tasks, file modes, checksums and credential settings
nginxL2Selected TLS, header, request and dry-run limit directives
HTTP headersL2Selected header declarations in supported server configuration files
Android manifestL2Selected exported-component, backup and transport settings
CI pipelinesL2Selected image, command and credential patterns
CloudFormationL2Selected resource, storage and policy declarations
BicepL2Selected storage, Key Vault, TLS, firewall and secure-parameter settings
OpenAPIL2Selected operation, authentication and schema declarations
PulumiL2Selected secret, resource and access-policy patterns
SQLL2Selected statements, procedures, definers and grants
SSH configurationL2Selected authentication, key-exchange and daemon settings
CrossplaneL2Selected connection-secret and managed-resource declarations
Serverless FrameworkL2Selected function role, environment and endpoint authoriser settings
HTMLL2Selected script, resource and form markup
Shell scriptsL2Selected eval, download-and-run, temporary file, TLS and permission patterns
PowerShellL2Selected Invoke-Expression, download-and-run, execution policy and TLS patterns
iOS property listL2Selected transport, sharing and application settings
JenkinsL2Selected pipeline, command and credential patterns
MavenL2Selected repository and dependency declarations
Spring propertiesL2Selected password and TLS properties
ASP.NET configurationL2Selected credential, cookie, debug and directory-browsing settings
PHP configurationL2Selected session and runtime settings
Java templatesL2Selected JSP and Thymeleaf output patterns
PHP templatesL2Selected Twig and Blade output patterns
JavaScript templatesL2Selected template output patterns

Every plan

Every surface is included.

No per-language pricing, no separate SAST, dependency, secrets or infrastructure products, no charge per scan and no premium export format. Every plan scans every surface; Business adds organisation features such as risk management and the software inventory; Enterprise adds single sign-on.

As scanning coverage grows, every plan receives the additions.

See pricing
Every language and format on this page
Every review surface: code, dependencies, inventories, cryptography, secrets, configuration
Malicious package detection and typosquatting heuristics
AI and ML component inventory (AIBOM) for recognised SDK and model patterns
Unlimited repositories and unlimited scans
All export formats: SARIF, CycloneDX, SPDX, CBOM, ML-BOM, HTML, CSV, XML, JSON
The dashboard, triage, decision history and reports
CLI-based CI workflows; runner setup and validation vary by platform
The magdox CLI and magdox-mcp server on Windows, macOS and Linux

A useful next conversation

Find the right product for your review workflow.

Tell us what you need to examine, where your work runs, and what evidence your team needs.

Contact about FDIE Discuss Code Security

Prefer to talk it through? Book a call with our team.