The Horusec homepage
Score7.3
Rank#2 of 24
PriceFree
Free planYes
Runs onAPI, Browser extension, Linux, macOS, Self-hosted, Web, Windows

Summary

Horusec is a static code analysis tool for finding security flaws during software development. It can scan source code and search project files and Git history for leaked keys and other security issues. The project describes analysis across 18 languages using 20 security tools; listed language coverage includes C#, Java, Kotlin, Python, Ruby, Golang, Terraform, JavaScript, TypeScript, Kubernetes, PHP, C, HTML, JSON, Dart, Elixir, Shell and Nginx. Analysis can be configured through CLI resources. Developers can run the command-line interface locally, and DevSecOps teams can use it in CI/CD pipelines; a Visual Studio Code extension is also available. Horusec-Web provides vulnerability dashboards, false-positive controls, authorization tokens and vulnerability updates. The platform integrates with the CLI to visualize and manage vulnerabilities and supports native Horusec, LDAP and Keycloak authentication. Its repository was archived by its owner on March 19, 2025 and is read-only. Running Horusec with all its tools requires Docker; the platform also requires RabbitMQ and PostgreSQL. The open-source plan is 0.00 USD per free under Apache License 2.0.

Who it is for

Horusec suits developers and DevSecOps teams seeking source analysis through a CLI, editor extension or CI/CD pipeline. Its web platform may be relevant to teams managing vulnerability findings, though its repository is archived and read-only.

What is good

  • Scans source code and Git history for leaked keys.
  • Supports CLI use and CI/CD pipelines.
  • Includes a Visual Studio Code extension.
  • Open-source plan is 0.00 USD per free.

What to know first

  • All analysis tools require Docker.
  • Disabling Docker reduces analysis capabilities.
  • Platform repository is archived and read-only.
  • Platform requires RabbitMQ and PostgreSQL.

Verdict

Horusec combines configurable code analysis with CLI, CI/CD and editor workflows. Account for its Docker requirement and the archived, read-only status of the platform repository before deciding whether its components suit your needs.

Horusec plans and pricing

All plans
Open source Free Apache License 2.0 · CLI and platform components github.com · 1 Oct 2026

Compared on static application security testing software

Free plan
Yesgithub.com
Analysis target
sourcegithub.com
IDE support
Yesgithub.com
CI/CD support
Yesgithub.com
Deployment
self-hostedgithub.com
SCA included
Yesgithub.com
Fix guidance
Yesgithub.com

Facts

Purpose
Horusec performs static code analysis to identify security flaws during development.github.com · 1 Oct 2026
Languages
It analyzes C#, Java, Kotlin, Python, Ruby, Golang, Terraform, JavaScript, TypeScript, Kubernetes, PHP, C, HTML, JSON, Dart, Elixir, Shell and Nginx.github.com · 1 Oct 2026
Secret detection
It searches project files and Git history for key leaks and other security flaws.github.com · 1 Oct 2026
Security tools
Horusec analyzes 18 languages with 20 different security tools simultaneously.github.com · 1 Oct 2026
Configurable analysis
The analysis is fully configurable through CLI resources.github.com · 1 Oct 2026
Developer workflow
Developers can use Horusec through its CLI, while DevSecOps teams can use it in CI/CD pipelines.github.com · 1 Oct 2026
Docker requirement
Docker is required to run Horusec with all its tools; disabling Docker loses much of the analysis power.github.com · 1 Oct 2026
Web application
Horusec-Web provides vulnerability metrics dashboards, false-positive control, authorization tokens and vulnerability updates.github.com · 1 Oct 2026
Editor integration
The project provides a Visual Studio Code extension for analyzing projects.github.com · 1 Oct 2026
Platform integration
Horusec Platform is a set of web services integrating with Horusec CLI to visualize and manage vulnerabilities.github.com · 1 Oct 2026
Platform authentication
Horusec Platform supports native Horusec, LDAP and Keycloak authentication.github.com · 1 Oct 2026
Platform dependencies
Horusec Platform requires RabbitMQ and PostgreSQL.github.com · 1 Oct 2026
Security policy
Zup's open-source projects adopt OpenSSF Security Scorecard and OpenSSF Best Practices Badge recommendations.github.com · 1 Oct 2026
Support
Questions and ideas are handled through GitHub Issues and the Zup Open Source Forum.github.com · 1 Oct 2026
Platform status
The Horusec Platform repository was archived by its owner on March 19, 2025 and is read-only.github.com · 1 Oct 2026

Best Horusec alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Horusec yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources