Scan a GitHub repo for risk.
Point Dralvia at a public GitHub repository and read its supply-chain and security posture, leaked secrets, risky dependencies, post-install scripts, and branch protection, with evidence.
Repository security
See Dralvia in action.
Review source packages for SBOM, secret, dependency, and provenance risks in one workflow.
- Submit a supported repository package
- Track the review
- Export evidence into existing AppSec workflows
This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Read the repo before you trust it.
Dependency walk
The full transitive tree, scored, with the deepest finding surfaced.
Secret scanning
Live tokens and keys surfaced from source with line-level evidence.
Repository signal
Branch protection, force pushes, contributor history, and risky CI configuration.
Honest answers.
Yes, with appropriate access on Pro and Enterprise; public repos work on the free tier.
Run a free check now.
No account needed for your first scan. See the verdict and the evidence behind it.