GitHubMate — Free AI Code Security Scanner | Security Knowledge Graph
GitHubMate scans any GitHub repository for AI-generated code risks, secrets, CVEs, and misconfigurations. It provides full OWASP LLM Top 10 (2025) and OWASP Top 10:2021 coverage — free, no signup, results in 30 seconds.
GitHubMate includes a unique Security Knowledge Graph (Attack Surface Map) that visualises how vulnerabilities, secrets, CVEs, source files, OWASP categories, and compliance frameworks interconnect in one interactive graph.
Please enable JavaScript to use GitHubMate.
Features
- Security Knowledge Graph — interactive Attack Surface Map connecting vulnerabilities, files, secrets, CVEs, OWASP categories, and compliance frameworks
- AI Fix Generator — AI-generated code fixes for each detected vulnerability
- Blast-radius scoring — identifies the top 3 highest-impact vulnerabilities to fix first
- OWASP LLM Top 10 (2025) — all 10 categories: LLM01 Prompt Injection through LLM10 LLM Jacking
- OWASP Top 10:2021 — all 10 categories: A01 Broken Access Control through A10 SSRF
- Vibe-code and AI-generated code risk detection
- Secret scanning: 30+ named token patterns + Shannon entropy (4.0 bits/char threshold)
- Live CVE lookup via OSV.dev across 8 ecosystems
- IaC scanning: Dockerfile, docker-compose, Kubernetes, Terraform, Fastlane
- SBOM export (JSON & CSV)
- OWASP ASVS Level 1/2/3 compliance scoring
- SOC 2, GDPR, HIPAA, PCI DSS readiness
- VS Code extension with inline diagnostics