█████╗ ██╗ ███╗ ██╗██╗ ██╗██████╗ ██╔══██╗██║ ████╗ ██║██║ ██║██╔══██╗ ███████║██║ ██╔██╗ ██║██║ ██║██████╔╝ ██╔══██║██║ ██║╚██╗██║██║ ██║██╔══██╗ ██║ ██║███████╗██║ ╚████║╚██████╔╝██║ ██║ ╚═╝ ╚═╝╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝
ALNUR is an open-source end-to-end security scanner. Point it at any project and get a full report — CVEs, secrets, architecture flaws, and port risks in seconds.
Run ALNUR against any directory and get a complete security report in seconds.
Five independent scanners work in parallel to give you a complete security picture.
Extracts all dependencies and queries the OSV.dev database for known CVEs. No API key needed. Returns severity, CVSS score, and fix version.
Finds hardcoded AWS keys, GitHub tokens, Stripe keys, JWTs, database URLs, and more using 18 named patterns plus Shannon entropy analysis.
30+ static analysis rules detect SQL injection, command injection, weak crypto, insecure deserialization, Django/Flask/Node misconfigurations, and more.
15 checks for software engineering best practices — .gitignore hygiene, dependency pinning, test suites, CI/CD configuration, and Docker security.
Scans Dockerfiles, docker-compose, .env files, and config files for dangerous port exposures — Redis, MongoDB, MySQL, Elasticsearch, and 25 more.
Every scan produces a 0–1000 risk score and A–F grade. Exits with code 1 on critical/high findings for seamless CI/CD pipeline integration.
Pass any project path. ALNUR auto-detects the project type and finds all dependency files.
CVE, secrets, architecture, standards, and port analyzers run in sequence on your codebase.
Console, JSON, or HTML — pick your format. Every finding includes a severity and fix recommendation.
No account. No API key. Just install and scan.
Color-coded Rich terminal output with severity tables, recommendations, and risk grade.
Structured machine-readable report. Perfect for CI/CD pipelines, dashboards, and tooling.
Self-contained dark-theme security dashboard. No external dependencies — share as a single file.
Free, open-source, and takes 30 seconds to set up. No signup required.