ScanRepo
PulseGate's liveness check found it on 9 Oct 2026; it is registered on GitHub and has been in the index since 8 Sep 2026. How this is checked
ScanRepo analyzes public GitHub and Bitbucket repository snapshots without cloning, installing, or executing their contents. It applies static rules and curated indicators to detect malware, credential theft, obfuscation, malicious dependencies, and other supply-chain risks.
Inferred · not functionally tested
Overview
6 featuresPurpose: Identifying malicious code and supply-chain threats in repositories before downloading or cloning them.
Inferred · not functionally tested
Audience: developers and security-conscious software teams
Inferred · not functionally tested
Functions: data_extraction
Inferred · not functionally tested
Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: unknown
Recorded constraints: pricing: free · license: Proprietary · platforms: CLI, WEB · deployment: browser, cli, cloud_managed
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: scanrepo.dev · github.com. These links do not verify the individual claims.
ScanRepo is an Application security & vulnerability scanning project. Inferred · not functionally tested: It focuses on identifying malicious code and supply-chain threats in repositories before downloading or cloning them. Inferred · not functionally tested: ScanRepo is a B2B product aimed at developers and security-conscious software teams. Basis unknown · not verified: ScanRepo costs nothing to use. Basis unknown · not verified: ScanRepo is available on the web and the command line.
ScanRepo first shipped in 2025. Development happens publicly on GitHub with 217 stars and 4 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include static analysis, risk scoring, and malware detection.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- Static analysis
- Risk scoring
- Malware detection
- Credential theft detection
- Supply-chain scanning
- Curated IoCs
Topics: Inferred · not functionally tested
Built with & integrations
- Next.js
- x-nextjs-prerender header · /_next/static/ in the HTML · __next_f in the HTML
- Vercel
- x-vercel-id header · x-vercel-cache header
Trust & compliance
Indexing history
1What PulseGate has recorded for this listing
- Indexed8 Sep · 18:25 UTCScan Before You Clone seen via Hacker News firehose (Algolia)Source: Hacker News firehose (Algolia) · Open
Frequently asked questions about ScanRepo
- What does ScanRepo do?
- Inferred · not functionally tested: ScanRepo focuses on identifying malicious code and supply-chain threats in repositories before downloading or cloning them. It is catalogued under Application security & vulnerability scanning on PulseGate.
- Who is ScanRepo for?
- Inferred · not functionally tested: ScanRepo is a B2B product built for developers and security-conscious software teams.
- Is ScanRepo free?
- Basis unknown · not verified: Yes — ScanRepo is free to use.
- What platforms does ScanRepo run on?
- Basis unknown · not verified: ScanRepo runs on the web and the command line.
- Is ScanRepo still maintained?
- PulseGate's liveness check found it on 9 Oct 2026. Its GitHub repository shows 4 commits in the last 90 days.
- What projects are similar to ScanRepo?
- Similar projects tracked by PulseGate include repo-security-scanner, repo-trust-scan, and repo-tester.repo-security-scannerrepo-trust-scanrepo-tester
- How long has ScanRepo been around?
- ScanRepo first shipped in 2025.
- Is ScanRepo open source?
- Basis unknown · not verified: ScanRepo has a public GitHub repository.
Similar projects
Closest matches by what these projects do