Paste any GitHub repo. Get an instant security score — secrets exposure, vulnerable dependencies, CVE risk, CI/CD gaps. Free tier available. No install required.
What Does the Score Mean?
ZaphScore analyzes any public GitHub repo across 12 security dimensions and returns a single score from 0 to 100. Higher is safer. Think of it like a credit score — but for code security.
Score is computed across: Secret Exposure · Dependency CVEs · CI/CD Security · Code Quality · License Risk · and 7 more phases.
12-Phase Analysis
Static metrics, complexity, dead code ratio.
Repo age, star velocity, contributor count.
Known CVEs, outdated packages, supply chain risk.
Frequency, contributor churn, bus factor.
Workflows, test automation, branch protection.
Unsafe functions, injection risk, code patterns.
Weighted aggregate, normalized 0–100 with percentile.
Score trajectory over 90 days.
Binary pass/fail for CI/CD pipeline integration.
Secrets, endpoints, public surface risk.
Identity signals, signed commits, author provenance.
Real-world threat intel cross-referenced with findings.
Pricing
Try it, no commitment.
For developers who ship secure code.
For security-conscious teams.
Unlimited. White-label. SLA.