7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Horusec

Open source

Horusec is a static application security testing tool that scans code in many languages for vulnerabilities and leaked secrets with one command.

GitHub stars
1.3k
Last commit
6 days ago
Repository age
6 years
Version
v2.8.0
Licence
Apache-2.0
Self-hosted
Yes

About Horusec

Horusec is an open-source tool for static code analysis focused on security. It scans a project for security flaws during development, and can also search for leaked keys and credentials in project files and in Git history, so issues are found before they reach production.

It supports a wide range of languages and formats, including Java, Kotlin, Python, Ruby, Go, JavaScript, TypeScript, PHP, C#, Dart, Elixir, Shell, Terraform, Kubernetes manifests and Nginx configuration. It orchestrates multiple analysis tools, which is why Docker is recommended, although a flag allows running without it at the cost of analysis power. It can be used from the command line by developers, in CI/CD pipelines by DevSecOps teams, through a web application and in Visual Studio Code.

Horusec is written in Go and licensed under Apache-2.0, with installers for Mac, Linux and Windows and documentation listing every supported tool and language. It runs on your own machines or build servers. It suits development teams that want free SAST scanning in their pipelines.

Key features

  • Static analysis across many languages
  • Secret and key leak detection
  • Scanning of Git history
  • CLI and CI/CD pipeline usage
  • Horusec-Web application
  • Visual Studio Code integration

Good fit for

  • →Adding SAST scans to a CI pipeline
  • →Finding committed secrets in a repository
  • →Giving developers local security checks
Tags
sast
security
static-analysis
vulnerability-scanner
devsecops
secrets
cli
go
ci

Horusec: questions and answers

What is Horusec used for?
Horusec is a static application security testing tool that scans code in many languages for vulnerabilities and leaked secrets with one command. It is a good fit for adding SAST scans to a CI pipeline, finding committed secrets in a repository and giving developers local security checks.
Is Horusec open source?
Yes. Horusec is open source under the Apache-2.0 licence. Its source code is on GitHub at ZupIT/horusec and is written mainly in Go.
Is Horusec free?
Yes. Horusec is open source, so the software itself is free to use.
What is Horusec an alternative to?
Horusec is an open-source alternative to Checkmarx, Veracode, Snyk and Aikido Security. Other open-source alternatives to Checkmarx include Grype, Semgrep and Trivy.
Is Horusec actively maintained?
Yes. The most recent commit to Horusec was on 26 September 2026, and the latest release is v2.8.0, published on 8 June 2022. The project has 1.3k stars on GitHub.

Open-source alternatives to Horusec

See all

SaaS alternatives to Horusec

See all