Paste a repository. Get security evidence.

RepoGuard pins one public GitHub repository to an exact commit, then scans it for risky code patterns, leaked secrets, and vulnerable dependencies. Repository code is never executed.

One required input

Send one public GitHub URL. RepoGuard resolves the default branch to a full 40-character commit before payment.

Three evidence classes

RepoGuard-owned Semgrep rules, Gitleaks secret detection, and OSV dependency advisories.

Machine-verifiable

Every delivery contains exact-input evidence, explicit limits, scanner status, and a content digest.

RepoGuard is a bounded static-analysis product, not a penetration test, certification, legal opinion, or guarantee of security. Current revenue is shown only from independently verified external settlements. Wallet authorization is processed by the injected wallet and x402 payment middleware; RepoGuard never requests or stores a private key.