GG Total Scanner runs 3 analysis engines in parallel on every PR — credential exposure, static code analysis and dependency vulnerabilities — and posts a Risk Score + detailed report before any merge happens.
| Severity | File | Finding |
|---|---|---|
| CRITICAL | src/config.js:42 | AWS Access Key (AKIA…) |
| HIGH | src/db/conn.js:8 | Hardcoded DB password |
| Severity | File | Finding |
|---|---|---|
| HIGH | src/routes/pay.js:91 | SQL Injection via raw query |
| MEDIUM | src/utils/log.js:17 | Sensitive data in logs |
| + 3 more findings Show all → | ||
| Severity | Package | CVE |
|---|---|---|
| HIGH | lodash@4.17.20 | CVE-2021-23337 |
Every time a pull request is opened or updated, GG Total Scanner triggers automatically — no manual intervention, no extra CI steps.
Developer opens or updates a pull request on any connected repository
Findings weighted by severity. Score from 0 to 100.
Detailed findings comment + check status on the PR
Audit: pass-through. Enforce: blocks on critical findings.
Each engine is purpose-built for its category. They run concurrently — the whole scan finishes in the time a single sequential pass would take.
Detects secrets committed to source code using entropy analysis, regex patterns and a 1,200+ rule database. Catches what regex alone misses.
Performs data-flow analysis across changed files to detect security vulnerabilities introduced by the PR — not just pattern matching, but actual taint tracking.
Scans lock files and manifests for known CVEs in direct and transitive dependencies. Flags outdated packages and license compliance issues.
The Risk Score aggregates findings from all three engines, weighted by severity, into a 0–100 score. Predictable. Auditable. Actionable.
Score is capped at 100. Any CRITICAL finding sets the score to at least 70 regardless of total.
Switch modes from the dashboard without touching any config file or pipeline. Start in Audit while your team learns the tool; move to Enforce when you're ready.
GG Total Scanner runs the full scan and posts the report — but the PR check always passes. Merge is never blocked, even for CRITICAL findings.
When CRITICAL findings are detected, GG Total Scanner marks the required check as failing. Your platform blocks the merge until issues are resolved or manually dismissed.
Findings organized by category, severity and file. Every finding links directly to the exact line. Developers get the context they need to fix — right in the PR.
Critical findings first. No noise before signal.
Credentials, SAST and dependencies each in their own section.
Every finding links to the exact location in the diff.
Every commit to the PR triggers a fresh scan. Report updates in-place.
| Severity | File | Line | Description |
|---|---|---|---|
| CRITICAL | src/config.js | #42 | AWS Access Key ID exposed (AKIA…B3J2) |
| HIGH | src/db/conn.js | #8 | Hardcoded database password |
| Severity | File | Line | Vulnerability |
|---|---|---|---|
| HIGH | src/routes/payment.js | #91 | SQL Injection via unsanitized query |
| HIGH | src/utils/response.js | #34 | Reflected XSS — user input unescaped |
| MEDIUM | src/utils/log.js | #17 | Sensitive data written to logs |
| MEDIUM | src/auth/token.js | #55 | JWT verified without algorithm check |
| LOW | src/middleware/cors.js | #12 | Overly permissive CORS origin |
| Severity | Package | CVE | Fix |
|---|---|---|---|
| HIGH | lodash@4.17.20 | CVE-2021-23337 | → 4.17.21 |
| MEDIUM | axios@0.21.1 | CVE-2021-3749 | → 0.24.0 |
| LOW | moment@2.29.1 | CVE-2022-24785 | → 2.29.2 |
GG Total Scanner is deployed and configured by our team. No self-serve setup — we ensure it works correctly for your repositories from day one.
Tell us about your stack, team size and repositories. We'll review and get back to you within one business day to schedule an onboarding call.
Request AccessWe integrate directly with your repository platform, configure each repository and help you choose between Audit and Enforce mode — based on your security posture and team workflow.
acme-corp/backend ● Enforce acme-corp/frontend ● Audit acme-corp/data-pipeline ● Audit
From the next PR forward, every merge attempt triggers a full scan automatically. Your developers get reports directly in the repository — no new tools, no new workflows.
GG Total Scanner — Risk Score: 72/100 Verdict: REJECTED — 2 critical findings detected Scanned 47 files across 3 engines in 38s