
Horusec
Summary
Horusec is a static code analysis tool for finding security flaws during software development. It can scan source code and search project files and Git history for leaked keys and other security issues. The project describes analysis across 18 languages using 20 security tools; listed language coverage includes C#, Java, Kotlin, Python, Ruby, Golang, Terraform, JavaScript, TypeScript, Kubernetes, PHP, C, HTML, JSON, Dart, Elixir, Shell and Nginx. Analysis can be configured through CLI resources. Developers can run the command-line interface locally, and DevSecOps teams can use it in CI/CD pipelines; a Visual Studio Code extension is also available. Horusec-Web provides vulnerability dashboards, false-positive controls, authorization tokens and vulnerability updates. The platform integrates with the CLI to visualize and manage vulnerabilities and supports native Horusec, LDAP and Keycloak authentication. Its repository was archived by its owner on March 19, 2025 and is read-only. Running Horusec with all its tools requires Docker; the platform also requires RabbitMQ and PostgreSQL. The open-source plan is 0.00 USD per free under Apache License 2.0.
Who it is for
Horusec suits developers and DevSecOps teams seeking source analysis through a CLI, editor extension or CI/CD pipeline. Its web platform may be relevant to teams managing vulnerability findings, though its repository is archived and read-only.
What is good
- Scans source code and Git history for leaked keys.
- Supports CLI use and CI/CD pipelines.
- Includes a Visual Studio Code extension.
- Open-source plan is 0.00 USD per free.
What to know first
- All analysis tools require Docker.
- Disabling Docker reduces analysis capabilities.
- Platform repository is archived and read-only.
- Platform requires RabbitMQ and PostgreSQL.
Verdict
Horusec combines configurable code analysis with CLI, CI/CD and editor workflows. Account for its Docker requirement and the archived, read-only status of the platform repository before deciding whether its components suit your needs.
Horusec plans and pricing
All plansCompared on static application security testing software
- Free plan
- Yesgithub.com
- Analysis target
- sourcegithub.com
- IDE support
- Yesgithub.com
- CI/CD support
- Yesgithub.com
- Deployment
- self-hostedgithub.com
- SCA included
- Yesgithub.com
- Fix guidance
- Yesgithub.com
Facts
- Purpose
- Horusec performs static code analysis to identify security flaws during development.github.com · 1 Oct 2026
- Languages
- It analyzes C#, Java, Kotlin, Python, Ruby, Golang, Terraform, JavaScript, TypeScript, Kubernetes, PHP, C, HTML, JSON, Dart, Elixir, Shell and Nginx.github.com · 1 Oct 2026
- Secret detection
- It searches project files and Git history for key leaks and other security flaws.github.com · 1 Oct 2026
- Security tools
- Horusec analyzes 18 languages with 20 different security tools simultaneously.github.com · 1 Oct 2026
- Configurable analysis
- The analysis is fully configurable through CLI resources.github.com · 1 Oct 2026
- Developer workflow
- Developers can use Horusec through its CLI, while DevSecOps teams can use it in CI/CD pipelines.github.com · 1 Oct 2026
- Docker requirement
- Docker is required to run Horusec with all its tools; disabling Docker loses much of the analysis power.github.com · 1 Oct 2026
- Web application
- Horusec-Web provides vulnerability metrics dashboards, false-positive control, authorization tokens and vulnerability updates.github.com · 1 Oct 2026
- Editor integration
- The project provides a Visual Studio Code extension for analyzing projects.github.com · 1 Oct 2026
- Platform integration
- Horusec Platform is a set of web services integrating with Horusec CLI to visualize and manage vulnerabilities.github.com · 1 Oct 2026
- Platform authentication
- Horusec Platform supports native Horusec, LDAP and Keycloak authentication.github.com · 1 Oct 2026
- Platform dependencies
- Horusec Platform requires RabbitMQ and PostgreSQL.github.com · 1 Oct 2026
- Security policy
- Zup's open-source projects adopt OpenSSF Security Scorecard and OpenSSF Best Practices Badge recommendations.github.com · 1 Oct 2026
- Support
- Questions and ideas are handled through GitHub Issues and the Zup Open Source Forum.github.com · 1 Oct 2026
- Platform status
- The Horusec Platform repository was archived by its owner on March 19, 2025 and is read-only.github.com · 1 Oct 2026
Best Horusec alternatives
See all 12Where it ranks on Everything Xiaomi
Is Horusec yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/ZupIT/horusec· checked 1 Oct 2026
- github.com/zup-archive/horusec-platform· checked 1 Oct 2026
- github.com/ZupIT/horusec/blob/main/SECURITY.md· checked 1 Oct 2026
- github.com/ZupIT/horusec-platform· checked 1 Oct 2026



