Recommended Tools

Curated security tools for every stage of your development workflow.

Bastion

Free
Code Scanning

Privacy-first security checker and educator for AI-era builders. Scans locally, never uploads code. Includes fix explanations and AI prompts.

Visit

eslint-plugin-security

Free
Code Scanning

ESLint rules that identify potential security hotspots in Node.js code. Detects eval, non-literal requires, and timing attacks.

Visit

GitHub Advanced Security

Freemium
Code Scanning

Code scanning (CodeQL), secret scanning, and dependency review built into GitHub. Catches vulnerabilities in pull requests.

Visit

SonarCloud

Freemium
Code Scanning

Cloud-based code quality and security analysis. Detects bugs, vulnerabilities, and code smells across 30+ languages.

Visit

Skylos

Free
Dead Code / SAST

Dead code detection with vibe coding detection capabilities for TypeScript and JavaScript projects. Finds unused exports, functions, types, and modules to reduce attack surface.

Visit

npm audit

Free
Dependency Scanning

Built-in Node.js dependency vulnerability scanner. Checks installed packages against the GitHub Advisory Database.

Visit

Snyk

Freemium
Dependency Scanning

Developer-first security platform. Finds and fixes vulnerabilities in dependencies, container images, and infrastructure as code.

Visit

Trivy

Free
Dependency Scanning

Comprehensive open-source vulnerability scanner. Scans container images, file systems, git repositories, and Kubernetes clusters.

Visit

Helmet.js

Free
HTTP Headers

Express.js middleware that sets security-related HTTP headers. Configures CSP, HSTS, X-Frame-Options, and more with sensible defaults.

Visit

Sentry

Freemium
Monitoring

Application monitoring and error tracking platform. Security-relevant for detecting anomalous errors, tracking release health, and monitoring performance.

Visit

Secretlint

Free
Secret Detection

Pluggable linting tool to prevent committing credentials. Supports AWS, GCP, npm tokens, private keys, and custom patterns.

Visit

Mozilla Observatory

Free
Site Scanner

Free online tool that analyzes your website's HTTP headers, TLS configuration, and other security best practices. Provides a letter grade.

Visit

OWASP ZAP

Free
Site Scanner

Free, open-source dynamic application security testing (DAST) tool. Actively scans running web applications for vulnerabilities.

Visit

Dependabot

Free
Supply Chain

GitHub-native automated dependency updates. Creates pull requests for outdated and vulnerable dependencies with changelogs.

Visit