SAST scanner inline in your editor. Detects IDOR, missing authorization, SQL injection, XSS, path traversal, and 30+ more CWE types — runs locally on your machine.
Features
🔍 Real-time scanning — findings appear inline as you type
🛡️ IDOR detection — catches authorization bugs other tools miss
📊 Trace-backed findings — see the full taint path from source to sink
🌐 5+ languages — Python, JavaScript/TypeScript, Go, Java, C#, and 35+ more
📋 SARIF output — one-click export for GitHub Code Scanning
🔒 Runs locally — scans files on your machine, no cloud required
⚡ Auto-detects guardmarly CLI — works with pip, pipx, or python -m