Powerful Analysis Engine

A multi-layer analysis engine with deep cross-corpus context — one of the most comprehensive code intelligence platforms available.

Core Analysis Services

File Scanner

Analyzes the major programming languages with role detection and framework identification. Understands your entire tech stack.

Active
Dependency Graph Builder

Extracts imports and builds directed acyclic graphs with cycle detection. Multi-language resolvers map your entire dependency tree.

Active
Symbol Extractor

Multi-language parsers extract functions, classes, and variables. Builds call graphs, inheritance trees, and detects API endpoints.

Active
Quality Analyzer

8-dimension quality scoring: code structure, code quality, documentation, testing, best practices, security posture, and dependency health.

Active
Credential Scanner

Curated regex set covering major cloud providers + common secret formats. Detect leaked API keys, tokens, and credentials before they ship.

Active
AI Reasoning

LLM-powered analysis for architecture patterns, data flow, and complex logic. Uses Claude, Ollama, or OpenAI for deep understanding.

Active

Extended Analysis

External Tool Runner

Integrates Trivy, Syft, Grype, Bandit, pip-audit, and RetireJS for comprehensive vulnerability detection.

SAST Engine

Custom taint analysis across major languages. Findings mapped to CWE and OWASP categories.

App Store Analyzer

Compliance checks against Google Play, Apple App Store, and Microsoft Store requirements.

Vulnerability Scanner

Real-time OSV API queries and CVE/NVD matching against all detected packages.

License Scanner

Identifies SPDX licenses. Classifies as permissive, copyleft, or proprietary for compliance.

Cognitive Complexity

SonarSource-style scoring for "how hard to understand" each function and module is.

Duplication Detector

Cross-file duplicate code block detection via rolling hash algorithms.

Tech Debt Estimator

Calculates remediation effort in hours, debt ratio percentage, and A-E debt rating.

DORA Metrics

Deploy frequency, lead time for changes, MTTR, and change failure rate from git history.

OWASP Classifier

Maps all security findings to OWASP Top 10 categories and CWE identifiers.

Quality Gates

Configurable pass/fail thresholds for CI/CD integration and release readiness.

Issue Tracker

Auto-creates issues from findings with full lifecycle management and status tracking.

Binary Security Analysis (20 Scanners)

Binary Composition Scanner

Analyzes ELF/PE binaries for composition vulnerabilities, triple patterns, and ROP gadgets across native code.

Attack Graph Builder

Maps exploit chains from entry points to privilege escalation targets. Visualizes multi-step attack paths.

Supply Chain Mapper

Traces transitive dependencies and identifies supply chain risk vectors with compound vulnerability scoring.

CVE Cross-Reference

Cross-references dependencies against NVD/CVE databases with compound risk scoring and exploitation probability.

CUDA Vulnerability Scan

Detects GPU kernel vulnerabilities, unsafe memory patterns, and side-channel risks in CUDA/OpenCL code.

Syscall Reachability

Maps application-to-kernel attack surface through syscall analysis and privilege boundary violations.

Intelligence Platform

Roast My Repo

Instant public code roast with AI-generated critique. Shareable results with permanent links and badge SVGs.

Stack Quality Oracle

Input your tech stack, get quality scores, security ratings, and similar high-quality repos using it.

Framework Intelligence

Deep-dive reports: language distribution, co-framework usage, size-grade correlation, and risk profiling per framework.

Private Code Intelligence

Workspace-scoped findings, compose sessions, risk summaries, and aggregate reports for private repositories.

Aggregate Research Reports

Public-safe briefs and benchmarks that summarize trends without exposing repositories, code, or raw provenance.

Quality Predictor

Predicts code quality grades using aggregate code intelligence signals and private workspace analysis.

Export Formats

JSON

CSV

PDF

SARIF

SBOM (CycloneDX)

SBOM (SPDX)

Recently Shipped

Scheduled Task Runner

Automated daily CVE sync, weekly repo re-analysis, and 60-second pending queue processing via Celery Beat.

Active
Vulnerability Alerts

Real-time CVE feed monitoring with per-repo alert subscriptions and email notifications for critical findings.

Active
Dashboard Charts

Interactive Chart.js visualizations: grade distribution, severity breakdown, language distribution, radar scores, and trend analysis.

Active
Binary Security Analysis

20 specialized scanners: ELF/PE analysis, attack graphs, supply chain mapping, CVE cross-reference, CUDA vulnerabilities, syscall reachability.

Active
Stack Oracle

AI-powered tech stack quality assessment. Input your frameworks, get quality scores, security ratings, and similar high-quality repos.

Active
DORA Metrics Dashboard

Deploy frequency, lead time, change failure rate, and MTTR computed from git history across all your repositories.

Active

Coming Soon

Provider Apps

Auto-analyze on push, post review comments with findings, and create issues across Git providers.

Planned
Incremental Analysis

Scan only changed files using git diff for 10x faster feedback on pull requests.

Planned
IDE Extensions

VS Code and JetBrains plugins with inline findings, AI fix prompts, and one-click remediation.

Planned