Repository Security Scanner
Repoloom scans your repositories for CVEs, exposed secrets, and security anti-patterns — before they reach production.
7 days free · No credit card required


Capabilities
Detect known CVEs across 12 package ecosystems before they become incidents.
Surface exposed API keys, tokens, and credentials hiding in your codebase.
31 rules catch SQL injection, XSS, command injection, and other anti-patterns across 8 languages.
Track end-of-life and deprecated packages so you never ship on abandoned foundations.
How it works
Link your GitHub account with read-only access. We never write to your repositories.
Choose which repositories to monitor. Set custom scan frequency for each.
Get actionable results in seconds, prioritized by severity and exploitability.
Pricing
Every plan includes a 7-day free trial. No credit card required.
FAQ