Install
Choose the signed native installer for your platform.
Run a local scan. See the exact file, rule, and fix path. Source code stays in your environment.
radar scan . --quickChoose the signed native installer for your platform.
Run one local command and inspect the exact finding evidence.
Fix, suppress, export, or promote only trusted signals to CI.
Find risky source patterns and insecure APIs before review.
↗02AI code reviewGive coding agents deterministic findings and scoped repair context.
↗03PR security gatesPromote trusted local evidence into SARIF and fail-on thresholds.
↗04Compare toolsEvaluate workflow fit with explicit criteria and boundaries.
↗The scanner runs on the developer machine or CI runner.
Repository content stays in the environment where the scan runs.
Generate SARIF, JSON, HTML, or agent context only when needed.
Code Radar is a local code security scanner for developers and small teams. It finds risky source patterns, exposed secrets, vulnerable dependencies, and code-health issues before review, then exports the evidence to reports, coding agents, or a pull-request gate when the team chooses.
Inspect this evidence: Judge the product by a finding you can inspect: affected file and line, rule identifier, severity, explanation, trace or dependency evidence, remediation direction, and a clean result after the fix.
Keep this limitation explicit: Radar does not promise to replace penetration testing, runtime testing, threat modeling, or a full enterprise AppSec platform. Static evidence still needs project context and accountable review.
Use the next step that matches the decision: Run Free Preview on a representative repository, inspect the sample report first if needed, and choose a paid plan only after the local evidence and workflow boundary are clear.
Verified benchmark
The figures below come from the repository's Criterion benchmark suite and include a reproducible environment, fixture, commit, and range.
10.703–10.819 ms
25.185–25.368 ms
13.494–13.586 ms
These measurements cover the maintained parser, rule, and scan-session fixture. They are not an end-to-end speed promise for every repository, machine, ruleset, or network condition.
Method →Use language-specific guidance to understand source checks, dependency coverage, evidence, and the local-to-CI workflow Code Radar can prove today.
↗02 / INTEGRATIONSSecurity evidence for the coding tools your team uses.Connect local Code Radar findings to coding-agent workflows, MCP context, repair prompts, and optional CI enforcement without turning review into guesswork.
↗03 / RULESRules that explain the risk, evidence, and fix.Review security, dependency, and code-health rules with concrete examples, detection boundaries, remediation guidance, and reproducible local commands.
↗Start with one local scan, inspect the evidence, and expand to reports, agents, or CI only when the signal is useful.