🔒 Open Source Security Tool

Scan any GitHub repo for
security nightmares
in 30 seconds.

Detect leaked secrets, vulnerable dependencies, misconfigured workflows, and insecure Dockerfiles. Get a security grade from A to F instantly.

Free for public repositories • No login required
🔑 Secret Detection
📦 Dependency Scan
🐳 Docker Security
⚙️ Actions Audit

What We Scan For

🔑

Secret Detection

Finds leaked API keys, tokens, passwords, private keys, and database URLs in your code.

📦

Dependency Vulnerabilities

Checks package.json, requirements.txt, and more for known CVEs and unpinned versions.

⚙️

GitHub Actions Audit

Detects unpinned actions, dangerous permissions, script injection, and supply chain risks.

🐳

Dockerfile Security

Flags running as root, unpinned base images, secrets in build args, and best practice violations.

📄

Gitignore Coverage

Ensures sensitive files like .env, private keys, and certificates are properly excluded.

📊

A-F Grade Report

Get an instant security grade with actionable recommendations for every finding.

Want to run it locally?

pip install shieldmyrepo && shieldmyrepo scan .
⭐ Star on GitHub 💡 Contribute