GitHubMate — Free AI Code Security Scanner
GitHubMate scans any GitHub repository for AI-generated code risks, secrets, CVEs, and misconfigurations. It provides full OWASP LLM Top 10 (2025) and OWASP Top 10:2021 coverage — free, no signup, results in 30 seconds.
Please enable JavaScript to use GitHubMate.
Features
- OWASP LLM Top 10 (2025) — all 10 categories: LLM01 Prompt Injection through LLM10 LLM Jacking
- OWASP Top 10:2021 — all 10 categories: A01 Broken Access Control through A10 SSRF
- Vibe-code and AI-generated code risk detection
- Secret scanning: 30+ named token patterns + Shannon entropy (4.0 bits/char threshold)
- Live CVE lookup via OSV.dev across 8 ecosystems
- IaC scanning: Dockerfile, docker-compose, Kubernetes, Terraform, Fastlane
- SBOM export (JSON & CSV)
- OWASP ASVS Level 1/2/3 compliance scoring
- SOC 2, GDPR, HIPAA, PCI DSS readiness
- VS Code extension with inline diagnostics