Works with any Git platform

Security review
on every Pull Request.
Automatically.

GG Total Scanner runs 3 analysis engines in parallel on every PR — credential exposure, static code analysis and dependency vulnerabilities — and posts a Risk Score + detailed report before any merge happens.

No code changes needed Works on every language Ready in under 2 minutes
acme-corp / backend #247 feat: add payment endpoint
● 1 check failing
gg-scannerbot 2 minutes ago
GG Total Scanner
REVIEW REQUIRED
72 / 100
2Critical
5High
3Medium
47 files · 38s · 3 engines
Credentials Exposure 2
SeverityFileFinding
CRITICAL src/config.js:42 AWS Access Key (AKIA…)
HIGH src/db/conn.js:8 Hardcoded DB password
SAST — Static Analysis 5
SeverityFileFinding
HIGH src/routes/pay.js:91 SQL Injection via raw query
MEDIUM src/utils/log.js:17 Sensitive data in logs
+ 3 more findings Show all →
Dependencies (SCA) 3
SeverityPackageCVE
HIGH lodash@4.17.20 CVE-2021-23337
3 Engines in parallel
<60s Average scan time
0 Code changes required
Any Language supported
HOW IT WORKS

From PR to verdict in seconds

Every time a pull request is opened or updated, GG Total Scanner triggers automatically — no manual intervention, no extra CI steps.

PR Opened

Developer opens or updates a pull request on any connected repository

3 Engines Scan in Parallel

Credentials SAST SCA

Risk Score Calculated

Findings weighted by severity. Score from 0 to 100.

Report Posted to PR

Detailed findings comment + check status on the PR

Merge Approved or Blocked

Audit: pass-through. Enforce: blocks on critical findings.

ANALYSIS ENGINES

Three engines. One scan.

Each engine is purpose-built for its category. They run concurrently — the whole scan finishes in the time a single sequential pass would take.

Credential Scanner

Secrets & Keys

Detects secrets committed to source code using entropy analysis, regex patterns and a 1,200+ rule database. Catches what regex alone misses.

Detects:
AWS / GCP / Azure keys API tokens & secrets Database passwords SSH private keys JWT secrets Stripe / Twilio keys Git tokens & PATs .env file leaks
1,200+ detection rules

SCA Engine

Dependency Vulnerabilities

Scans lock files and manifests for known CVEs in direct and transitive dependencies. Flags outdated packages and license compliance issues.

Detects:
Known CVEs (NVD + OSV) Outdated packages Transitive deps License violations Malicious packages npm / pip / maven go.sum / Cargo.lock Composer / Gemfile
CVE database (NVD + OSV)
RISK SCORE

A single number. Full context behind it.

The Risk Score aggregates findings from all three engines, weighted by severity, into a 0–100 score. Predictable. Auditable. Actionable.

0 50 100
Low Medium High

How it's calculated

CRITICAL
+40 pts each
HIGH
+25 pts each
MEDIUM
+15 pts each
LOW
+5 pts each

Score is capped at 100. Any CRITICAL finding sets the score to at least 70 regardless of total.

APPROVED Score ≤ 40 with no CRITICAL findings
REVIEW REQUIRED Score 41–69 or any HIGH finding
REJECTED Score ≥ 70 or any CRITICAL finding
OPERATION MODES

Audit or Enforce — you choose per repo

Switch modes from the dashboard without touching any config file or pipeline. Start in Audit while your team learns the tool; move to Enforce when you're ready.

AUDIT MODE

Report. Don't block.

GG Total Scanner runs the full scan and posts the report — but the PR check always passes. Merge is never blocked, even for CRITICAL findings.

  • Full scan + report on every PR
  • Risk Score and verdict visible
  • Check status: always green
  • Merge is never blocked
  • Ideal for onboarding and legacy repos
  • Teams see issues without friction
gg-scanner / audit — Report available
vs
Switch modes anytime from the dashboard — no YAML, no config files, no redeploys.
PR REPORT

The report your team actually reads

Findings organized by category, severity and file. Every finding links directly to the exact line. Developers get the context they need to fix — right in the PR.

Prioritized by severity

Critical findings first. No noise before signal.

Grouped by engine

Credentials, SAST and dependencies each in their own section.

File + line references

Every finding links to the exact location in the diff.

Re-runs on push

Every commit to the PR triggers a fresh scan. Report updates in-place.

gg-scannerbot just now edited
GG Total Scanner — Risk Score: 72/100 Verdict: REJECTED — 2 critical findings detected Scanned 47 files across 3 engines in 38s
Credentials Exposure — 2 findings
SeverityFileLineDescription
CRITICALsrc/config.js#42AWS Access Key ID exposed (AKIA…B3J2)
HIGHsrc/db/conn.js#8Hardcoded database password
SAST — Static Analysis — 5 findings
SeverityFileLineVulnerability
HIGHsrc/routes/payment.js#91SQL Injection via unsanitized query
HIGHsrc/utils/response.js#34Reflected XSS — user input unescaped
MEDIUMsrc/utils/log.js#17Sensitive data written to logs
MEDIUMsrc/auth/token.js#55JWT verified without algorithm check
LOWsrc/middleware/cors.js#12Overly permissive CORS origin
Dependencies (SCA) — 3 findings
SeverityPackageCVEFix
HIGHlodash@4.17.20CVE-2021-23337→ 4.17.21
MEDIUMaxios@0.21.1CVE-2021-3749→ 0.24.0
LOWmoment@2.29.1CVE-2022-24785→ 2.29.2
GET STARTED

From first contact to live protection.

GG Total Scanner is deployed and configured by our team. No self-serve setup — we ensure it works correctly for your repositories from day one.

1

Request access

Tell us about your stack, team size and repositories. We'll review and get back to you within one business day to schedule an onboarding call.

Request Access
2

Onboarding call with our team

We integrate directly with your repository platform, configure each repository and help you choose between Audit and Enforce mode — based on your security posture and team workflow.

gg-scanner dashboard — configured by our team
acme-corp/backend       ● Enforce
acme-corp/frontend      ● Audit
acme-corp/data-pipeline ● Audit
3

Your team is protected

From the next PR forward, every merge attempt triggers a full scan automatically. Your developers get reports directly in the repository — no new tools, no new workflows.

gg-scanner — Scan complete · View report