Find risky code before it reaches review.

Run a local scan. See the exact file, rule, and fix path. Source code stays in your environment.

radar scan . --quick
01

Install

Choose the signed native installer for your platform.

02

Scan

Run one local command and inspect the exact finding evidence.

03

Decide

Fix, suppress, export, or promote only trusted signals to CI.

Local execution

The scanner runs on the developer machine or CI runner.

No source upload

Repository content stays in the environment where the scan runs.

Exports by choice

Generate SARIF, JSON, HTML, or agent context only when needed.

What Code Radar is—and where it fits

Code Radar is a local code security scanner for developers and small teams. It finds risky source patterns, exposed secrets, vulnerable dependencies, and code-health issues before review, then exports the evidence to reports, coding agents, or a pull-request gate when the team chooses.

  • Judge the product by a finding you can inspect: affected file and line, rule identifier, severity, explanation, trace or dependency evidence, remediation direction, and a clean result after the fix.
  • Radar does not promise to replace penetration testing, runtime testing, threat modeling, or a full enterprise AppSec platform. Static evidence still needs project context and accountable review.
  • Run Free Preview on a representative repository, inspect the sample report first if needed, and choose a paid plan only after the local evidence and workflow boundary are clear.

What evidence should I inspect for What Code Radar is—and where it fits?

Inspect this evidence: Judge the product by a finding you can inspect: affected file and line, rule identifier, severity, explanation, trace or dependency evidence, remediation direction, and a clean result after the fix.

What does What Code Radar is—and where it fits not prove?

Keep this limitation explicit: Radar does not promise to replace penetration testing, runtime testing, threat modeling, or a full enterprise AppSec platform. Static evidence still needs project context and accountable review.

What should I do after reviewing What Code Radar is—and where it fits?

Use the next step that matches the decision: Run Free Preview on a representative repository, inspect the sample report first if needed, and choose a paid plan only after the local evidence and workflow boundary are clear.

Verified benchmark

Measured on a maintained fixture, not invented for a landing page.

The figures below come from the repository's Criterion benchmark suite and include a reproducible environment, fixture, commit, and range.

Measured
2026-08-08
Version
1.0.0 · 0fb2efc
Method
Criterion 0.5.1 · radar-bench/parse_and_query
TypeScript parse · cache miss10.753 ms

10.703–10.819 ms

All maintained AST rules25.266 ms

25.185–25.368 ms

Scan summary · empty cache13.538 ms

13.494–13.586 ms

FixtureSynthetic TypeScript · 5,002 lines · 130,884 bytes
EnvironmentApple M2 · 8 cores · 16 GB · macOS 27.0 · arm64
MethodOptimized bench profile · 3 s warm-up · 100 measured samples
Scope boundary

These measurements cover the maintained parser, rule, and scan-session fixture. They are not an end-to-end speed promise for every repository, machine, ruleset, or network condition.

Method →

Validate the workflow on your own code.

Start with one local scan, inspect the evidence, and expand to reports, agents, or CI only when the signal is useful.