Topic

Tools for finding security holes in code

202

we track

198

answered today

11

arrived this week

1

stopped answering

3 we couldn't reach today; we don't claim those are dead. Watching this group for 26 days, checked once a day · how we check

An open-source runtime for building and running production AI agent systems, for developers who don't want to hand-roll retrieval, memory, and execution logic.

Open sourceSelf-hosted
What to know
How it works
Handles retrieval, memory, model routing, and verification instead of hardcoded pipelines
What's different
Self-hostable, open-source, with governed execution including planning, verification, and replay
Best for
Developers building production AI systems in Python or Go
Details →

HeimWall

LiveWatched 15d

Local macOS scanner that blocks secrets and PII from leaking into AI coding-tool prompts, for engineers who don't want to rely on cloud DLP.

FreeWorks offline
What to know
How it works
A macOS app that scans prompts in real time before they reach AI coding tools like Cursor, Claude Code, and Copilot, flagging leaked API keys, credentials, and PII using 47 local detection rules in under 50ms.
What's different
Detection happens on-device before data leaves the machine, and uses soft notifications instead of hard blocks so it doesn't interrupt the coding flow.
Pricing
Free 15MB macOS application for engineers; an early-access dashboard is offered separately for organizations.
Best for
Engineers using AI coding assistants who want to avoid pasting live secrets into prompts.
Details →

Ask your cloud anything without breaking prod. Read-only.

Open source
What to know
How it works
Her çağrı IAM aksiyonlarına çözümlenip salt-okunur politikaya karşı yetkilendirilir; altyapıyı değiştiremez, script bazlı sandbox'ta çalışır.
What's different
MCP araçlarının aksine her turda sandbox'ta script yazar, tek bir sabit çağrı değil.
Details →

Kapient

LiveWatched 12d

Monitors your website's uptime, SSL, DNS, and email deliverability, and gives specific repair steps tailored to your actual hosting/CMS setup instead of generic advice.

What to know
How it works
Detects your tech stack, then generates setup-specific fix instructions when something breaks
What's different
Gives tailored instructions instead of a generic alert
Best for
Site owners/agencies who don't want to diagnose issues themselves
Details →

Panguard.AI

LiveWatched 14d

Open-source malware scanner and runtime guard for AI agents

FreeWorks offlineOpen source
What to know
How it works
Vets AI agent skills and MCP servers for malicious behavior before install, scans what's already installed, and blocks hijack attempts at runtime, using 768 open ATR rules.
What's different
Scanned 96,096 published skills and found 751 malicious; rules already merged into Microsoft, Cisco, MISP, and OWASP tooling.
Pricing
Free, MIT licensed, fully on-device.
Details →

Keelscan

LiveWatched 12d

A scanner that continuously checks your app's code and Supabase/Firebase config for security holes that could stall a B2B deal.

What to know
How it works
Scans code, live app and Supabase/Firebase for security issues, produces plain-English fixes and a shareable report
Best for
founders preparing for B2B or healthcare deal security reviews
Details →

Merges CVSS, EPSS, KEV, and CVE.org data into one unified per-vulnerability severity record, for anyone deciding what to patch first instead of checking four separate sources.

No sign-up
What to know
How it works
Ingests NVD, CISA KEV, FIRST EPSS, and CVE.org into one pipeline covering hundreds of thousands of CVEs, running them through a priority-based severity engine to serve a unified record — CVSS, EPSS percentile, KEV status, affected vendors/products, and weaknesses — per CVE.
What's different
Built on Cloudflare's edge with a continuously running collection pipeline and visible source-freshness status.
Details →

WebSlurp

LiveWatched 16d

A free, open-source Chrome DevTools extension for testing APIs — capture, inspect, edit, and replay HTTP requests without an external proxy, plus a quick header and secrets audit.

FreeOpen source
What to know
How it works
A Chrome DevTools extension that captures, inspects, edits, and replays HTTP/HTTPS requests without an external proxy, plus a Quick Security Check that audits headers and flags secrets or PII.
What's different
Works without needing to route traffic through an external proxy, unlike typical API testing setups.
Pricing
Free and open-source.
Best for
Developers testing API security directly inside Chrome DevTools.
Details →

HOL Guard

LiveWatched 10d

Free open-source firewall that sits between AI agents and your systems to block risky actions like deleting production data.

FreeOpen source
What to know
How it works
Intercepts agent actions before execution and blocks high-risk ones
Pricing
Free, open source
Best for
Developers running AI agents with system access they want to constrain
Details →

IPCheckly

LiveWatched 24d

An IP intelligence API that flags VPNs, proxies, Tor nodes and other fraud signals for geolocation, access control and fraud prevention. A developer and business security API.

What to know
How it works
An API that returns IP intelligence — location, network, VPN, proxy, and Tor node detection — with real-time data for fraud and risk signals.
Best for
Developers and businesses building fraud prevention, geolocation, or access-control features.
Details →

Versio

LiveWatched 14d

Paste in a package.json and get a dependency health dashboard, CVE vulnerability report, and project-specific migration guide.

What to know
How it works
Paste a package.json and get a dependency health dashboard, CVE vulnerability report, and a project-specific migration guide.
Best for
Developers who want to understand and fix risky or outdated dependencies quickly.
Details →

Keyline

LiveWatched 13d

Zero-knowledge secrets manager that lets small dev teams share encrypted .env files and revoke a person's access in one command, instead of pasting secrets in chat or shared docs.

Free
What to know
How it works
Secrets are encrypted client-side (AES-256-GCM, X25519 device keys) before upload; servers only ever hold ciphertext, and the audit log is hash-chained and publicly anchored.
Pricing
Solo is free; Team is $19 flat for up to 10 people with a 14-day trial.
Best for
Small dev teams sharing environment secrets.
Details →

Paste a suspicious text or email and get a 0-99 scam-risk score based on urgency, impersonation and gift-card-demand patterns. Free, instant, no account needed.

FreeNo sign-upNothing to install
What to know
How it works
Paste a suspicious SMS, email, or DM and get a 0-99 scam-risk score based on pattern matching for urgency language, lookalike domains, gift-card demands, and bank/USPS impersonation.
Pricing
Free.
Best for
Anyone who receives a suspicious message and wants a quick risk check without creating an account.
Details →

Debugging tool for developers that captures and explains SAML AuthnRequests/Responses across common identity providers.

Can export my data
What to know
How it works
Captures AuthnRequests and SAML Responses, correlates requests with responses, explains common configuration mistakes, flags protocol/security issues, and exports redacted diagnostics.
What's different
Built for Keycloak, Okta, Entra ID, Auth0, ADFS, Ping Identity, and any SAML 2.0 provider.
Best for
Developers and identity engineers.
Details →

Synapsor Runner

LiveWatched 11d

A tool that replaces raw SQL access for AI database agents with human-approved, scoped business actions instead of full read/write authority.

No sign-upWorks offline
What to know
How it works
tenant-scoped semantic tools like billing.propose_late_fee_waiver; writes need human approval outside the model's reach
What's different
includes a CLI audit command to score an existing MCP setup's risk
Pricing
local-first, open source (Apache-2.0), no account needed
Details →

Shieldome

LiveWatched 11d

A vulnerability scanner and dark-web breach monitor for agencies and freelancers who want enterprise-grade security scans without a subscription.

No subscription
What to know
How it works
DAST scanning plus dark-web leak monitoring, accessible via API
What's different
pay-per-scan tokens instead of subscription, white-label resale for agencies
Pricing
pay-as-you-go tokens or SaaS plan
Details →

kritt.ai

LiveWatched 11d

An open-source platform for orchestrating LLM-based security research pipelines across vulnerability discovery and code analysis.

Open source
What to know
How it works
chains LLMs and custom agents into reusable security research workflows
Pricing
open source
Details →

Pipelock

LiveWatched 13d

Local firewall binary that sits between AI agents and the network to block secret leaks, prompt injection, SSRF, and MCP tool poisoning, for developers running autonomous agents, producing a signed offline-verifiable receipt instead of blind trust.

No sign-upWorks offlineOpen source
What to know
How it works
A single Go binary scans every outbound request from an agent and writes a signed receipt you verify offline against a published key when it blocks something.
Pricing
Apache 2.0, install via brew.
Best for
Developers whose AI agents have shell access, secrets, and an open line to the internet.
Details →

decloak.dev

LiveWatched 10d

Scans apps built with Lovable, Supabase, Base44, or Bolt for the security misconfigurations AI builders commonly leave, like an unprotected Supabase database.

FreeNo sign-up
What to know
How it works
auto-detects your platform and checks 8 security layers including exposed API keys
Pricing
free, no account or card required
Best for
vibe-coders shipping apps on no-code/AI platforms
Details →

Sindook Steward

LiveWatched 10d

An open-source local tool for planning and executing encrypted-file key rotation with AI-assisted threat interpretation and policy controls.

Open source
What to know
How it works
An open-source local tool that turns recipient changes into reviewable key-rotation plans, with AI interpreting threat signals while deterministic policy controls approval and execution.
What's different
Keys, plaintext, and ciphertext never pass through the model; includes a bundled post-quantum sample vault run with Docker.
Details →

VulnWatch Agency

LiveWatched 6d

Branded website security reports for digital agencies

What to know
How it works
Aylık tam rapor tarama kredisi ile müşteriye kendi logonuzla rapor verirsiniz, imzalı paylaşımlarda SaaS arayüzü gizlenir.
Details →

Cairn

LiveWatched 9d

Local-first Terraform scanner that audits cost, security and reliability in one pass with no upload, MIT licensed.

No sign-upWorks offlineData stays with you
What to know
How it works
Scans Terraform locally for security, cost, reliability, and governance issues in one pass, and writes the patch when a cost fix and a security risk hit the same resource.
What's different
No account, no upload, zero network calls.
Pricing
Free, MIT licensed.
Details →

Tell Me When Down

LiveWatched 9d

Uptime, free security scan and GitHub-connected CVE/secret monitoring for solo founders' sites, with copy-paste AI fixes.

Free
What to know
How it works
Watches sites at three depths: a free public security scan (SSL, headers, DNS, spoofing), a read-only GitHub App finding CVEs and leaked secrets, and an SDK covering DB, Stripe webhooks, and cron jobs, with checks every 60s and copy-paste AI fixes.
Pricing
Free security scan.
Best for
Solo founders.
Details →

A tool that checks public HTTPS endpoints for SSL certificate expiry, trust, hostname match, and chain issues, and exports results to an Apify dataset or API.

Can export my data
What to know
How it works
Checks expiry, trust, hostname match, TLS, HSTS, redirects, issuer, SANs, and certificate-chain data for public endpoints.
Best for
Developers, agencies, and IT teams exporting certificate health into an existing workflow.
Details →

Argus

LiveWatched 12d

Runs multiple security scanners (gitleaks, semgrep, trivy, syft) on your Git repos and uses AI to de-duplicate findings and flag logic/business-flow bugs the scanners miss into one report.

Self-hosted
What to know
How it works
combines multiple scanners, AI reviewer verifies and de-dupes findings
What's different
self-hostable, catches logic bugs pattern scanners miss
Details →

A mobile threat and CVE alerting app that filters ongoing exploit activity down to what applies to your specific tech stack, instead of tracking every vulnerability disclosure yourself.

What to know
How it works
You enter your tech stack once; it then watches actively exploited vulnerabilities, filters to what applies to your stack, and sends a short daily briefing on what to do.
Best for
CISOs and security teams who need to prioritize which vulnerabilities actually matter to them.
Details →

Scans your codebase for quantum-vulnerable cryptography ahead of the post-quantum transition.

What to know
How it works
Scans code to flag cryptographic algorithms vulnerable to quantum attacks.
Best for
Engineering teams preparing for post-quantum cryptography migration.
Details →

Depheal

LiveWatched 13d

An offline scanner that checks Python projects for known CVE vulnerabilities using local AST analysis, instead of a cloud-based dependency scanner.

Works offlineOpen source
What to know
How it works
Static AST analysis run entirely locally, with no internet connection or external dependencies required.
Pricing
Open source, published on PyPI.
Best for
Developers who want fast vulnerability scanning without sending code to a cloud service.
Details →

Aether Injector

LiveWatched 15d

A Windows DLL injector with stealth/evasion techniques built for security researchers and low-level Windows tinkerers testing memory manipulation, not a general consumer tool.

Watch out · Marketed around stealth and bypassing detection engines — intended for security testing, not general use.

What to know
How it works
A Windows DLL injector built in C++20 offering 8 injection methods and evasion parameters designed to bypass static heuristic detection engines.
Best for
Security researchers and advanced Windows users doing memory manipulation and security testing.
Watch out
Marketed around stealth and bypassing detection engines — intended for security testing, not general use.
Details →

CertLocker

LiveWatched 14d

Centralizes TLS certificate, ACME, secrets, and SSH access management with infrastructure health monitoring, built for SRE and DevOps teams.

What to know
How it works
Centralizes management of TLS certificates, ACME automation, secrets, and SSH access tokens, with infrastructure health monitoring via endpoint probes across bare metal, VMs, and hybrid environments.
Best for
SRE and DevOps teams.
Details →

Python Code Audit

LiveWatched 11d

Scans Python code for security vulnerabilities using static analysis, aimed at developers checking code they use or ship.

What to know
How it works
static application security testing (SAST) for Python packages and files
Details →

PreRiskAI

LiveWatched 7d

Lets SaaS teams self-assess security readiness before an audit instead of paying for consulting review.

Free
What to know
Pricing
free self-assessment
Details →

Sentinel DNS

LiveWatched 7d

Lets ISPs and telecoms run DNS filtering and threat intelligence instead of relying on closed enterprise appliances.

Open source
What to know
Best for
ISPs, datacenters and telecoms
Details →

Keyholdr

LiveWatched 15d

A macOS app storing API keys in the Keychain, unlocked via Touch ID and a hotkey, with a CLI for injecting secrets.

Watch out · macOS only.

No tracking
What to know
How it works
Press a hotkey (⌃⌥⌘K) anywhere on macOS to open a vault requiring Touch ID for every copy; keys are stored in the macOS Keychain and organized by platform and tag with multi-select copying; ships with a CLI (keyholdr pick / run) to inject secrets as env vars without a .env file.
What's different
Single-purpose, unlike full password managers — no accounts, sync, analytics, or network access.
Watch out
macOS only.
Details →

Kosuke Pentest

LiveWatched 16d

A free web-app penetration testing service that shows the volume of security findings before charging to unlock the full report.

Free
What to know
How it works
Runs an automated penetration test on a web application in under 24 hours, identifying critical, high, and medium security issues and showing the volume of findings before purchase.
Pricing
Free to run; pay to unlock the full detailed report with proofs of concept and specific fixes.
Details →

AgentGuard

LiveWatched 10d

An intent-based firewall for AI agents that blocks unauthorized actions even when they pass rule-based spending limits.

No sign-up
What to know
How it works
Adds an AI intent firewall between your agents and the real world that can block actions whose intent doesn't match authorization, even when they pass spend-limit rules.
What's different
Includes a human approval gate and a tamper-evident ledger you can try breaking yourself.
Pricing
Live demo available with no signup or API key required.
Details →

A WordPress security plugin adding firewall, malware scanning, and login hardening in one dashboard — for site owners, agencies, and developers managing WordPress sites.

Free
What to know
How it works
A WordPress security plugin combining security hardening, firewall and bot protection, login security with 2FA and CAPTCHA, vulnerability monitoring, audit logs, and cloud-assisted malware scanning.
What's different
Essential security hardening is available for free via simple toggles, without complicated configuration.
Pricing
Free tier for core hardening features.
Best for
WordPress site owners, agencies, and developers who want protection without complex setup.
Details →

Affordable security audits for early-stage SaaS teams, offering OWASP/API penetration testing with plain-English fix reports.

What to know
How it works
Delivers a report with proof-of-concept for each vulnerability and clear fix steps
Pricing
Quick scan from $50, full audit $250, delivered in days
Details →

flaw.co

LiveWatched 8d

A free external security scan that finds exposed AI/MCP endpoints and other misconfigurations before attackers do, instead of relying only on inside-the-cloud visibility.

FreeNo sign-up
What to know
How it works
Passive scan across MCP/AI exposure, TLS, headers, exposed ports, and disclosure using just your domain; findings map to PCI requirements.
Pricing
Free for the first scan, no account required.
Best for
Teams running AI agents/MCP servers who want an outside-in exposure check.
Details →

An attack surface monitoring tool for small and mid-size businesses that finds exposed subdomains, open ports, and misconfigured cloud buckets before attackers do.

What to know
Best for
SMBs wanting to see their external security exposure.
Details →

WordSec

LiveWatched 9d

A WordPress security suite bundling a firewall, malware scanner, 2FA, and CVE alerting.

What to know
How it works
Bundles a WordPress firewall, malware scanner with one-click repair, 2FA/captcha/lockouts, IP/country blocking, live traffic view, and CVE alerts with an audit log.
What's different
Alerts reach you by email, Telegram, or Slack, and scanner repairs infected files in one click.
Best for
WordPress site owners wanting an all-in-one security suite.
Details →

Mutagen

LiveWatched 9d

Open-source agentic AI fuzzer that finds bugs across languages and generates verified security patches automatically.

Open source
What to know
How it works
Uses a multi-agent LLM swarm to analyze source code or decompiled binaries, synthesize payloads, reproduce crashes and generate verified security patches automatically.
What's different
Supports C/C++, Rust, Python, Go, JS/TS and multiple LLM providers including Gemini, Claude, OpenAI and Ollama.
Pricing
Free, open-source.
Best for
Security researchers and developers doing automated fuzzing and patching.
Details →

CVEScan

LiveWatched 9d

Free runtime CVE scanner that matches installed software or scan results against known vulnerabilities and suggests patches.

FreeNo sign-up
What to know
How it works
Scans installed software, nmap XML output, or a public site, matches products to CPEs and CVEs against the NVD, and helps you find official patches.
Pricing
Free.
Best for
Security-conscious users on Mac, Linux, or Windows checking for known vulnerabilities.
Details →

Tenant Hawk

LiveWatched 24d

A read-only scanner that checks Microsoft 365 and Azure tenants for security gaps and estimates the dollar cost of unused licenses, starting with a free scan.

What to know
How it works
A read-only scanner that connects to Microsoft 365 and Azure via admin consent, then produces a 0-100 health score, a prioritized fix list, and dollar estimates for wasted licenses. It also checks MFA gaps, Global Admin sprawl, Conditional Access, legacy auth, guest access and SharePoint sharing.
What's different
Read-only and agentless — no stored credentials, tokens minted on demand — and combines security risk with dollar cost in one score instead of a raw alert list.
Pricing
Free scan available with score, severity breakdown and top findings.
Best for
IT admins and MSPs managing Microsoft 365/Azure tenants who need a prioritized, dollar-quantified fix list.
Details →

Free website security scanner that checks for malware, vulnerable plugins, and blocklist status with no signup.

FreeNothing to install
What to know
How it works
Scans front-end and back-end for malware, WordPress plugin vulnerabilities, and blocklist status
Pricing
free instant scan; $9/site/year for daily automated scans with email reports
Best for
Site owners wanting a quick security check without installing anything
Details →

Janus Shield

LiveWatched 13d

A cybersecurity tool that rehearses realistic attack paths against a company's authorized environment and produces executive-ready, prioritized remediation reports, instead of just listing vulnerabilities.

What to know
How it works
simulates attacker paths without requiring passwords or making production changes.
Best for
security teams needing business-focused, executive-ready reporting.
Details →

LeakCheck

LiveWatched 21d

Windows software that checks your passwords and email addresses against known data-breach databases locally on your PC, without sending sensitive data elsewhere.

Free
What to know
How it works
Windows software that checks your passwords and email addresses against known data-breach databases directly on your PC.
What's different
Runs the check locally on your PC without sending sensitive data elsewhere.
Pricing
Free to check.
Best for
Windows users who want to know if their credentials have appeared in known data leaks.
Details →

Offload Security

LiveWatched 10d

A unified security platform combining cloud, code, container and Kubernetes vulnerability findings into one risk dashboard.

What to know
How it works
Consolidates CNAPP, vulnerability management and compliance findings across infrastructure into one view
Pricing
Not stated
Best for
Security teams needing a single view across cloud/code/container risk
Details →

ironrun

LiveWatched 10d

An open-source encrypted workspace that gives AI agents time-boxed, secret-redacted access to run commands with your credentials.

Open source
What to know
How it works
An encrypted workspace that stores secrets and grants AI agents time-boxed access, injecting secrets into commands and redacting them from output.
Pricing
Open-source.
Details →

Cleanton

LiveWatched 10d

Mac app that clears build-cache disk space and scans your installed npm/pip packages for supply-chain malware before you approve deleting or acting.

What to know
How it works
reclaims disk space from build caches/apps/junk, learns your normal packages, flags new or changed suspicious ones
What's different
deletions go to Trash by default, requires your review before acting
Best for
Mac developers managing disk space and package security
Details →

Iron Shield

LiveWatched 15d

Enterprise security · Built for SMEs

Self-hosted
What to know
How it works
A security and compliance platform combining shadow AI, prompt injection, and deepfake detection with cloud, endpoint, and identity scanning (35+ scanners, agents for Linux/Windows/macOS/K8s), a self-hosted LLM gateway, and automated ISO 27001/GDPR compliance.
What's different
Built for 10-500 person companies that don't have a dedicated SOC team, unlike enterprise security tools that assume one.
Pricing
From $149/month, live within 30 minutes.
Best for
Small and mid-size companies without an in-house security operations team.
Details →

Strike48 Pick

LiveWatched 16d

A free, open-source, MIT-licensed penetration-testing agent bundling 90+ recon tools (nmap, nuclei, sqlmap and more) into a three-agent pipeline — for security engineers running assessments from the command line.

FreeOpen source
What to know
How it works
A reconnaissance agent that runs from inside the environment being tested (desktop, mobile, terminal or headless), bundling 90+ pentest tools like nmap, nuclei, sqlmap and aircrack-ng, plus native port scanning, device enumeration, WiFi discovery and packet capture. A three-agent pipeline (red team, validator, report) turns recon into verified findings.
What's different
Single Rust/Dioxus codebase across desktop, mobile, terminal and headless environments, and is MIT licensed so it can be inspected and extended.
Pricing
Free and open-source, MIT licensed.
Best for
Security engineers running penetration tests who want a bundled, extensible recon and reporting agent.
Details →

Z6 PQC-Gateway

LiveWatched 16d

A post-quantum encryption gateway that compresses ML-KEM handshake payloads below the network MTU to cut latency spikes from packet fragmentation.

What to know
How it works
Compresses hybrid ML-KEM-768 post-quantum handshake payloads below the network MTU using geometric lattice constraints, avoiding the packet fragmentation that spikes latency.
What's different
Keeps p99.9 tail latency flat at 6.8ms under concurrent load versus 38.2ms for standard payloads, per its own benchmark telemetry.
Details →

VulnScanners

LiveWatched 24d

A hosted console that runs Nmap, Nuclei and OWASP ZAP vulnerability scans with client-ready reports, aimed at MSPs, pentesters and security teams.

Nothing to install
What to know
How it works
A hosted console that runs Nmap, Nuclei and OWASP ZAP vulnerability scans with no local install, producing client-ready reports; credits don't expire.
Best for
MSPs, pentesters and security teams who need to run scans and hand clients a report.
Details →

Stamptcha

LiveWatched 11d

Replaces reCAPTCHA-style image-grid puzzles with a 4-second wax-seal interaction to prove you're human without tracking cookies.

Watch out · self-hosted/open-source version not yet released

What to know
How it works
a 4-second wax-seal ritual instead of image-grid puzzles
What's different
no cookies, no Google tracking, ~17kb, works on mobile
Watch out
self-hosted/open-source version not yet released
Details →

Spring Sentinel

LiveWatched 11d

Open-source static analysis tool that scans Spring Boot codebases for performance, security and architecture problems before they ship.

Open source
What to know
How it works
static analysis across Maven/Gradle/SpotBugs projects, outputs HTML/JSON/SARIF/CI reports
Pricing
open source
Best for
Spring Boot developers wanting automated code review in CI
Details →

ReadySECURE

LiveWatched 11d

A security platform combining vulnerability management, device management, C-suite reporting, and security training, integrating with tools like Qualys and Microsoft 365.

What to know
How it works
Combines vulnerability management, device management, C-suite reporting, security training, and forensics, set up in under 10 minutes.
What's different
Integrates with Qualys, Microsoft 365, Azure, Defender EDR+VM, and Huntress.
Details →

BugBounty Arsenal

LiveWatched 15d

A continuous security scanner that re-checks targets on a schedule and alerts only on new vulnerability findings.

FreeOpen source
What to know
How it works
Schedules recurring security scans (daily/weekly/monthly) with 50+ detectors across recon, web, API, and mobile, alerting via email/Discord/Slack only on new findings versus the previous run; tracks attack surface over time and ships a CLI plus GitHub Action to fail CI builds on new criticals.
What's different
Alerts only on new findings instead of re-reporting everything on each run, and remembers triage decisions across re-scans.
Pricing
Free, open source.
Details →

Complyeah

LiveWatched 18d

AI-run external penetration tests that produce SOC 2/ISO 27001-ready reports and certificates, paid per test with no subscription - the free scan is just an entry point, not the whole product.

No subscription
What to know
How it works
Runs AI-driven external penetration tests mapped to SOC 2 and ISO 27001, then generates auditor-ready pentest reports and shareable certificates. Starts with a free posture scan before you purchase individual tests.
What's different
Flat per-test pricing with no recurring subscription, and explicitly positioned to also work for vibe-coded apps.
Pricing
Free posture scan to start; individual tests purchased for a flat fee, no subscription.
Best for
Companies needing SOC 2 or ISO 27001-mapped pentest reports without committing to a subscription service.
Details →

Pentestr

LiveWatched 17d

Scans a web app for TLS, header and vulnerability issues and returns a graded report in minutes, aimed at dev teams who'd otherwise pay for a manual pentest.

What to know
How it works
Runs an automated web security audit in under 5 minutes, checking TLS/SSL configuration, security headers, WAF effectiveness, exposed ports, email spoofing risks (SPF/DKIM/DMARC), tech-stack exposure, and over 50,000 Nuclei templates for CVEs and misconfigurations, then returns a severity-based A-F report with remediation steps.
What's different
Automates checks across 8 areas that would otherwise require hiring a consultant for a manual pentest.
Best for
Development teams who want a fast security posture check without hiring a pentest consultant.
Details →

The ones we've read

Exfault

LiveWatched 9d

A tool that runs AI agents in cloud emulators to autonomously test Android apps for security vulnerabilities.

What to know
How it works
Deploys AI agents in cloud emulators to run static and dynamic analysis (using adb, jadx, apktool, frida, hermes-dec) on Android apps, including authenticated user flows, and generates reproducible security findings.
What's different
Only requires an Android package name, no APK/AAB upload needed.
Details →

Agentinel

LiveWatched 14d

A free, locally-run guardrail that intercepts hallucinated or malicious npm packages before AI coding agents like Claude Code or Cursor can install them.

What to know
How it works
Integrates at the hook level to intercept hallucinated and malicious npm packages before AI coding agents like Claude Code or Cursor can execute them, checking against a 60,000+ threat database in under 2ms.
Pricing
Zero-cost, locally run.
Details →

A demo cybersecurity project that encrypts and monitors simulated brain-computer-interface signal data for injection, replay, and flatline attacks, visualized in a live dashboard.

Watch out · Runs on simulated data rather than real BCI hardware and was built as a learning project by a self-taught builder.

What to know
How it works
Uses AES-256 encryption, HMAC device authentication, and real-time anomaly detection on simulated EEG data, shown in a live browser dashboard.
Watch out
Runs on simulated data rather than real BCI hardware and was built as a learning project by a self-taught builder.
Details →

Aria-Sec

LiveWatched 6d

AI security that earns your trust before it acts

What to know
How it works
Önce onay ister, her sonucu doğrular ve zamanla dar kapsamlı özerklik kazanır; kendi kendini yetki yükseltemez.
Details →

AI Code Prep v2

LiveWatched 7d

Lets developers pack large codebases into an LLM-friendly format instead of manually copying files into ChatGPT or Claude.

What to know
How it works
Rust rewrite with compression modes and secrets detection/redaction to keep API keys off your machine's output.
Details →

openbait

LiveWatched 23d

An anti-phishing security product aimed at mid-market companies; the listing gives no detail on how the protection actually works.

What to know
How it works
An anti-phishing SaaS product.
Best for
Mid-market companies wanting phishing protection.
Details →

RepoAI.io

LiveWatched 6d

The security-scored directory for MCP servers

What to know
How it works
213 MCP sunucusuna 0-100 güvenlik skoru, 5 AI istemcisi için hazır konfig ve insan editör hükmü verir; ücretli yerleştirme yok.
What's different
Skorlar ve verdict insan editör tarafından yazılır, kazınmış ya da AI üretimi pazarlama metni değil.
Details →

Veridome Surface

LiveWatched 7d

Lets people who built apps with AI tools like Lovable or Cursor find and fix real security exposures instead of guessing what's unsafe.

What to know
How it works
Checks the live app on every deploy and hands you a fix prompt written for the AI tool you build with.
Details →

Just arrived

VibeCodersLegal

LiveFirst seen today
No sign-up
Details →

Clavera AI

LiveFirst seen today
Details →

LTH Shield

LiveFirst seen today
Details →

OpeClaud Ai

LiveWatched 2d
FreeOpen source
Details →

Fidacy

LiveWatched 2d
FreeWorks offline
Details →

Nexora Shield

LiveWatched 2d
FreeNo sign-up
Details →

Soterios

LiveWatched 2d
Works offlineOpen source
Details →

Watched the longest, still answering

RedScore

LiveWatched 26d

Scans any domain in about 60 seconds and produces a 0-100 security score with letter grades across 10 areas, for anyone checking a website's security posture without signing up.

FreeNo sign-up
What to know
How it works
Scans a domain in about 60 seconds across 10 security areas and returns a score, letter grades, and recommended fixes.
Pricing
Free, no account required.
Details →

Perfai Security

LiveWatched 24d

Find & fix live vulnerabilities in Vibe Apps with 1-prompt.

Watch out · Automated one-prompt fixes are the vendor's claim; the page doesn't say how fixes are verified before or after they're applied.

What to know
How it works
Scans apps built with AI coding tools (Replit, Lovable, Claude Code, Cursor and similar) for live access-control vulnerabilities and can fix them automatically from a single prompt.
What's different
Targets 'vibe-coded' apps specifically — code generated by AI tools — rather than general application security scanning.
Best for
People who shipped an app using an AI coding tool without security expertise and want vulnerabilities found and patched automatically.
Watch out
Automated one-prompt fixes are the vendor's claim; the page doesn't say how fixes are verified before or after they're applied.
Details →

Hexical AI

LiveWatched 24d

A multi-agent AI tool that automates vulnerability scanning and exploit-payload generation for developers.

What to know
How it works
Deploys multi-agent Red and Blue team swarms to analyze AST flows, run heuristic reconnaissance, and generate exploit payloads from a command center.
What's different
Positions itself as a hybrid intelligence engine with a cyber-elegant HUD for routing analysis across local and global compute nodes.
Best for
Developers automating vulnerability intelligence and diagnostics.
Details →

SBOMix

LiveWatched 24d

Scans your codebase to generate standard SBOM files plus an inventory of the AI models, API providers and MCP servers your code uses. A free CLI for developers, not an API product itself.

Free
What to know
How it works
Scans a repo and produces standard SBOM output (CycloneDX, SPDX) plus an AI-BOM listing the models, API providers and MCP servers the code calls, each with its authority scope.
What's different
Standard SBOM tools don't surface a codebase's AI stack or the agents in it; SBOMix adds that layer.
Pricing
Free CLI, with an optional dashboard.
Best for
Developers who need to inventory not just dependencies but the AI models and agents their code relies on.
Details →

agentsweep

LiveWatched 24d

Find & redact leaked secrets in AI coding-agent history

What to know
How it works
Scans the history of AI coding agents (such as Claude Code) to find leaked secrets like API keys and passwords, then redacts them.
Best for
Developers who want to check their AI coding-agent history for accidentally exposed credentials.
Details →

Furgle Ai

LiveWatched 24d

Scans your codebase for security vulnerabilities and helps developers understand and fix them inside their normal workflow, for engineering teams.

What to know
How it works
Scans a codebase to detect security vulnerabilities and helps developers understand and remediate them from inside their normal development workflow.
Best for
Engineering teams that want AI-assisted vulnerability detection and fixes without leaving their existing workflow.
Details →

twSecScan

LiveWatched 24d

A single-binary desktop app that scans websites, APIs and OSINT sources for security issues — a scanning tool for security-minded developers, not a hosted API service itself.

What to know
How it works
A zero-dependency desktop security scanner, built with Wails and Svelte 5, that runs from a single binary to scan websites, APIs, and OSINT sources for security issues.
Best for
Security-focused developers who want a local scanning tool rather than a hosted scanning service.
Details →

A security scanning tool that red-teams an LLM endpoint with adversarial test cases and produces an audit report mapped to the OWASP LLM Top 10.

What to know
How it works
Red-teams the LLM endpoint with adversarial test cases and delivers a security audit report mapped to OWASP LLM Top 10.
Details →

Stopped answering

LaunchGuardian

Not respondingWatched 6d

Know if your AI-built app is actually production-ready

What to know
How it works
Tarama sonuçlarını tarama-üstü-tarama izler, iyileşme/kötüleşmeyi gösterir; bulduğu sorun için gerçek PR açar.
Pricing
İlk tarama ücretsiz.
Details →

Opviva

LiveWatched 22d

An AI security agent that scans a live app for vulnerabilities like exposed keys and broken access control, proves each exploit is real, and opens a pull request with the fix, for developers shipping AI-built apps, instead of manual security audits.

FreeNo sign-up
What to know
How it works
Scans your live app, reproduces each exploit to prove it's real, then opens the fix as a pull request you approve; keeps watching after launch.
Pricing
Free security scan, no signup.
Details →

VOUCH

LiveWatched 21d

Scores open-source projects on safety, maintenance and popularity so developers can compare tools before adopting them, instead of picking by star count alone.

FreeNo sign-upNo ads
What to know
How it works
Scores open-source projects on safety (via OSSF Scorecard and advisories), maintenance, popularity, and lightweightness, and lets you AI-compare projects side by side.
What's different
Scores tools on safety and maintenance signals rather than letting users pick by star count alone.
Pricing
Free, no login, no ads.
Best for
Developers evaluating which open-source project to trust and adopt.
Details →

Share-Env

LiveWatched 19d

A secure way for teams to share .env files and secrets via expiring links and role-based access, instead of pasting them into Slack, email, or chat history.

Free
What to know
How it works
Generates expiring share links, invites teammates by email, and manages access via workspace roles, with row-level security and encryption at rest.
Pricing
free
Best for
development teams sharing environment secrets
Details →

Bleek.dev

LiveWatched 23d

A free web scanner that checks apps built with Lovable, Bolt or v0 for leaked API keys, open databases and missing security headers, no signup needed.

FreeNo sign-up
What to know
How it works
Scans apps built with tools like Lovable, Bolt or v0 for issues those builders tend to skip: leaked API keys, publicly readable databases, and missing security headers.
What's different
Targets the specific gaps left by AI app-building tools rather than doing generic security scanning.
Pricing
Free, no signup.
Best for
People who built an app with an AI app builder and want a quick check for exposed keys or open databases.
Details →

VulX Watch

LiveWatched 5d
Free
Details →

VirtuProbe Studio

LiveWatched 6d

Cross-protocol integration testing tool (HTTP, DNS, SMTP, IMAP, LDAP, MySQL, MongoDB, PostgreSQL, SMB, Kerberos, SpamAssassin) that chains steps together, with an MCP-connected coding-agent mode in 2.0.

FreeNo sign-upCan export my data
Details →

qsa.sh

LiveWatched 5d
FreeNo sign-up
Details →

gate.cat

LiveWatched 4d

Blocks rm -rf before your AI agent can run it

Free
Details →

An open-source reference guide covering AI and ML security practices, including LLM, RAG, agent, and MLOps supply-chain controls, for developers and ML engineers.

Open source
What to know
How it works
Documents practical MLSecOps guidance across AI security, ML security, LLM/RAG/agent security, and ML supply-chain controls.
Best for
Developers and ML engineers securing AI/ML systems.
Details →

PathDeck

LiveWatched 23d

A free, open-source macOS app for editing your $PATH, aliases and environment variables through a drag-and-drop UI instead of hand-editing shell config files.

Open source
What to know
How it works
A macOS app with a drag-and-drop dashboard for editing your $PATH, toggling shell aliases, and managing environment variables, with sensitive keys secured behind Touch ID.
What's different
Replaces hand-editing shell config files with a visual UI, and is under 1.4MB, open source, built in SwiftUI.
Pricing
Open source.
Best for
Developers on macOS who are tired of manually editing dotfiles to manage PATH, aliases and env variables.
Details →

Caputchin

LiveWatched 24d

A drop-in CAPTCHA replacement — a short reaction game easy for humans and hard for bots — that collects no visitor IP, fingerprint or tracking data, with an open-source widget.

Open sourceNo tracking
What to know
How it works
Replaces the usual CAPTCHA puzzle with a short reaction-based game; every round is re-checked on the server, so it's easy for humans but hard for bots and AI solvers.
What's different
Collects no IP, fingerprint, or tracking data about visitors, and the widget and games are open source for developers to inspect and restyle.
Best for
Developers who want a privacy-respecting, open-source CAPTCHA alternative for their site.
Details →

Virgil

LiveWatched 4d

A security scanner that tells you what not to fix

FreeOpen source
Details →

ThreatLens

LiveWatched 5d
FreeOpen source
Details →

Sunglasses

LiveWatched 5d
No sign-upWorks offlineOpen source
Details →

krain

LiveWatched 5d
Open sourceSelf-hosted
Details →

ASL V6

LiveWatched 5d
FreeOpen source
Details →

CheckCyber

LiveWatched 5d
No sign-upNothing to install
Details →

Impersona

LiveWatched 6d

Free EU-hosted brand-protection tool that watches Certificate Transparency logs for typosquat and lookalike domains.

FreeNo sign-up
Details →

Malinois

LiveWatched 6d

Free external security check for AI-built web apps you own or have permission to test — checks what a normal visitor can see (security headers, public configuration, client-side secrets, data-store references) and explains it in plain language. No login, exploitation or private-network scanning.

FreeNo sign-up
Details →
No sign-upWorks offlineNo subscription
Details →

AI Cyber Shield

LiveWatched 2d
FreeNo sign-up
Details →

Tools for finding security holes in code — the short answers

Every number here comes from our own daily check — not from a vendor list.

Tools for finding security holes in code — how many are there?
Tablif is tracking 202 of them. 198 answered our check today, and 3 we couldn't reach — we don't claim those are dead.
Which ones are still maintained?
Tablif knocks on every door once a day and records the answer. 198 of these 202 responded on the latest run, so that number is what "still here" means on this page — not a review score.
Are any of them free?
39 of the live ones say so in their own words, and 23 let you start without making an account. Tablif records the claim the product makes; we don't verify pricing.
Any open-source options?
27 of the live ones on Tablif mention being open source.
What's the newest one?
VibeCodersLegal — Tablif first saw it today.
Did a person actually look at these?
200 of them Tablif opened and read, then wrote a one-line summary in our own words instead of reusing the founder's tagline. The rest carry keyword labels we haven't confirmed by reading yet — and we say so rather than hiding it.