Your app shipped fast. Find out what it left open.
Point Codanopy at a repository and it runs a multi-analyzer static review plus an AI pass that reads across files. The scan itself is free, every time. You get a score, a summary, and a severity breakdown of everything found.
What we look for
What the AI pass finds that rules can't
Pattern matchers look at one file at a time. Most of the damage in an AI-generated app comes from how two files relate to each other — and that is structurally invisible to a rule.
Stacks supported
Docker and Terraform files are detected and read for configuration issues. The stack is worked out from your files — you don't declare it.
Limits, stated plainly
- 20 MB
- of scannable source per repo, and at most 5,000 source files.
- 50 MB
- maximum ZIP upload size.
- 3 / hour
- and 10 per day, per person. Enough to re-scan after a fix.
How the score works
Findings are weighted by severity into a score from 0 to 100, then given a letter. The same repo always scores the same way.
- A
- 90 – 100
- B
- 75 – 89
- C
- 60 – 74
- D
- 40 – 59
- F
- below 40
One CRITICAL finding caps the score at 75 — a B at best.
No amount of clean code buys back an A while a live secret is in your repo. If you see a B or lower with a CRITICAL present, the cap is why — and clearing that one finding is the fastest possible score change.
We would rather show you an honest C than a flattering A. A score you can game is a score a client can't trust.