Powerful Analysis Engine

48+ services working together to give you complete visibility into your codebase

Core Analysis Services

File Scanner

Analyzes 50+ programming languages with role detection and 75+ framework identification. Understands your entire tech stack.

Active
Dependency Graph Builder

Extracts imports and builds directed acyclic graphs with cycle detection. 16 language-specific resolvers map your entire dependency tree.

Active
Symbol Extractor

16 language parsers extract functions, classes, and variables. Builds call graphs, inheritance trees, and detects API endpoints.

Active
Quality Analyzer

8-dimension quality scoring: code structure, code quality, documentation, testing, best practices, security posture, and dependency health.

Active
Credential Scanner

135 regex patterns detect leaked API keys, tokens, and secrets across 200+ cloud services. Prevent credential exposure.

Active
AI Reasoning

LLM-powered analysis for architecture patterns, data flow, and complex logic. Uses Claude, Ollama, or OpenAI for deep understanding.

Active

Extended Analysis (15 Sub-Services)

External Tool Runner

Integrates Trivy, Syft, Grype, Bandit, pip-audit, and RetireJS for comprehensive vulnerability detection.

SAST Engine

Custom taint analysis with 30 rules across 6 languages. All findings mapped to CWE and OWASP categories.

App Store Analyzer

Compliance checks against Google Play, Apple App Store, and Microsoft Store requirements.

Vulnerability Scanner

Real-time OSV API queries and CVE/NVD matching against all detected packages.

License Scanner

Identifies 30+ SPDX licenses. Classifies as permissive, copyleft, or proprietary for compliance.

Cognitive Complexity

SonarSource-style scoring for "how hard to understand" each function and module is.

Duplication Detector

Cross-file duplicate code block detection via rolling hash algorithms.

Tech Debt Estimator

Calculates remediation effort in hours, debt ratio percentage, and A-E debt rating.

DORA Metrics

Deploy frequency, lead time for changes, MTTR, and change failure rate from git history.

OWASP Classifier

Maps all security findings to OWASP Top 10 categories and CWE identifiers.

Quality Gates

Configurable pass/fail thresholds for CI/CD integration and release readiness.

Issue Tracker

Auto-creates issues from findings with full lifecycle management and status tracking.

Export Formats

JSON

CSV

PDF

SARIF

SBOM (CycloneDX)

SBOM (SPDX)

Coming Soon

Scheduled Task Runner

Automated re-checks against new CVEs without full re-analysis.

Planned
Incremental Analysis

Scan only changed files using git diff for faster feedback.

Planned
Notification System

Email, Slack, and Telegram alerts for critical vulnerabilities.

Planned
GitHub App

Auto-analyze on push, post PR comments with findings.

Planned
Dashboard Charts

Sparklines, trend lines, and pie charts for all metrics.

Planned
IDE Extensions

VS Code and JetBrains plugins with inline findings.

Planned