GitHub security scanner
Live

Scan a GitHub repo for risk.

Point Dralvia at a public GitHub repository and read its supply-chain and security posture, leaked secrets, risky dependencies, post-install scripts, and branch protection, with evidence.

✓Dependencies + secrets✓Repository posture✓Free to start
Product preview

Repository security

See Dralvia in action.

Review source packages for SBOM, secret, dependency, and provenance risks in one workflow.

  • Submit a supported repository package
  • Track the review
  • Export evidence into existing AppSec workflows

This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Dralvia Repository Risk Scanner workspace preview
Product preview · Repository Risk Scanner
What it does

Read the repo before you trust it.

Dependency walk

The full transitive tree, scored, with the deepest finding surfaced.

Secret scanning

Live tokens and keys surfaced from source with line-level evidence.

Repository signal

Branch protection, force pushes, contributor history, and risky CI configuration.

FAQ

Honest answers.

Yes, with appropriate access on Pro and Enterprise; public repos work on the free tier.

Run a free check now.

No account needed for your first scan. See the verdict and the evidence behind it.