About Horusec
Horusec is an open-source tool for static code analysis focused on security. It scans a project for security flaws during development, and can also search for leaked keys and credentials in project files and in Git history, so issues are found before they reach production.
It supports a wide range of languages and formats, including Java, Kotlin, Python, Ruby, Go, JavaScript, TypeScript, PHP, C#, Dart, Elixir, Shell, Terraform, Kubernetes manifests and Nginx configuration. It orchestrates multiple analysis tools, which is why Docker is recommended, although a flag allows running without it at the cost of analysis power. It can be used from the command line by developers, in CI/CD pipelines by DevSecOps teams, through a web application and in Visual Studio Code.
Horusec is written in Go and licensed under Apache-2.0, with installers for Mac, Linux and Windows and documentation listing every supported tool and language. It runs on your own machines or build servers. It suits development teams that want free SAST scanning in their pipelines.
Key features
- Static analysis across many languages
- Secret and key leak detection
- Scanning of Git history
- CLI and CI/CD pipeline usage
- Horusec-Web application
- Visual Studio Code integration
Good fit for
- →Adding SAST scans to a CI pipeline
- →Finding committed secrets in a repository
- →Giving developers local security checks
- Tags
- sast
- security
- static-analysis
- vulnerability-scanner
- devsecops
- secrets
- cli
- go
- ci
Horusec: questions and answers
- What is Horusec used for?
- Horusec is a static application security testing tool that scans code in many languages for vulnerabilities and leaked secrets with one command. It is a good fit for adding SAST scans to a CI pipeline, finding committed secrets in a repository and giving developers local security checks.
- Is Horusec open source?
- Yes. Horusec is open source under the Apache-2.0 licence. Its source code is on GitHub at ZupIT/horusec and is written mainly in Go.
- Is Horusec free?
- Yes. Horusec is open source, so the software itself is free to use.
- What is Horusec an alternative to?
- Horusec is an open-source alternative to Checkmarx, Veracode, Snyk and Aikido Security. Other open-source alternatives to Checkmarx include Grype, Semgrep and Trivy.
- Is Horusec actively maintained?
- Yes. The most recent commit to Horusec was on 26 September 2026, and the latest release is v2.8.0, published on 8 June 2022. The project has 1.3k stars on GitHub.
Open-source alternatives to Horusec
See all
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
SonarQube
Developer Tools
Continuous Inspection
LGPL-3.0vs Codacy★ 11k
tfsec
Security
Tfsec is now part of Trivy
MITvs Aikido Security★ 7k
SaaS alternatives to Horusec
See all
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Mend
Security
Application security platform for software composition analysis and code scanning
SaaS
Black Duck
Security
Software composition analysis and application security testing products
SaaS
