Source code vulnerability scanner with actionable findings.

Radar focuses on source-code vulnerabilities reviewers need before merge: injection paths, unsafe auth, traversal, secrets, and risky APIs.

radar scan . --quick

Local static checks

Rules run in the local engine and produce actionable finding records with file, severity, confidence, and fix guidance.

  • SQL injection
  • Command injection
  • Path traversal
  • Hardcoded secrets

Evidence to inspect

Use “Source code vulnerability scanner with actionable findings.” as the scope for this decision: verify the input, finding detail, workflow handoff, and product boundary before you install or buy.

CriterionEvidence to inspectBoundary
Input scopeSelected files, configuration, scan mode, and enabled rules.Only included paths and configured checks are evaluated.
Finding detailFile, line, rule ID, severity, explanation, and repair direction.Illustrative output is not a result from your repository.
Workflow handoffLocal result, report format, agent context, and optional CI signal.Enable exports or CI only when the workflow needs them.
Decision fitUse the same criteria on a real repository before choosing a plan or tool.No universal winner or guaranteed outcome is claimed.

Run this check locally

Evidence over scores

Each finding can include why it matters, how to fix it, and a copy-ready prompt for your coding agent.

Validate the workflow on your own code.

Apply this page’s evidence to one real repository. For “Source code vulnerability scanner with actionable findings.”, confirm which finding is produced, whether the proposed next step is reproducible, and where local scanning, reports, agents, or CI should stop or expand.