Scan your code. Fix it before they exploit it.
Spartyx finds SQL injection, XSS, command injection, hardcoded secrets and 30+ vulnerability types across your codebase — with cross-file taint tracking, in 14 languages.
5 FREE SCANS / MONTH · PUBLIC REPOS · 14 LANGUAGES
File paths, line numbers, CVSS scores
Every finding comes back with where it is, how bad it is, and the remediation steps to fix it.
It follows the input, not the line
Tracks user input across files to the exact line where it becomes exploitable — routes.py:18 → db.py:42.
Real AST parsing
Python, JavaScript, TypeScript, Go, Java, Ruby, PHP, Rust, Kotlin and more.
CVE matching, live
npm, PyPI and Go modules checked against OSV, NVD, GitHub Advisories, CISA KEV and Exploit-DB.
PDF you can forward
CVSS scores, CWE mapping, attack paths and copy-paste remediation steps in one export.
Watch a scan run.
Static analysis, cross-file taint tracking and AI review run together. Scroll to play it through.
Professional-grade scanning, without the enterprise price tag.
Cross-file taint analysis
Tracks user input across files to the exact line where it becomes exploitable. Not a single-file pattern match — the whole path, from entry point to the statement that runs it.
14 programming languages
Python, JavaScript, TypeScript, Go, Java, Ruby, PHP, Rust, Kotlin and more — all parsed into real syntax trees rather than matched with regular expressions.
GitHub integration
Connect a repository in one click and scan any branch or any commit, public or private.
AI deep review
A Gemini-powered pass that catches complex logic flaws regex and AST scanners miss.
Dependency scanning
CVE matching for npm, PyPI and Go modules through OSV, layered with NVD, GitHub Advisories, CISA KEV and Exploit-DB. A package on the CISA Known Exploited list is raised to critical; an Exploit-DB match adds a public-exploit signal.
Professional reports
PDF export with CVSS scores, CWE mapping, attack paths and copy-paste remediation steps.
From repo to report.
Connect
Paste a GitHub URL, upload your codebase, or enter a website to scan.
Scan
The engine runs static analysis, cross-file taint tracking and AI review simultaneously.
Fix
Get prioritised findings with file paths, line numbers, CVSS scores and exact remediation steps.
Free during beta.
No credit card. Public repos, 14 languages, results in minutes.
Beta
- 5 scans a month
- Public repositories
- Ghost Mode included
- All 14 languages
- PDF report export
Pro
- Private repositories
- CI/CD integration
- Leave your email and we'll tell you first
- You don't need this to start scanning today
Ghost Mode is our free baseline scan — fast, deterministic static analysis that flags vulnerabilities, hardcoded secrets, and risky configuration in your code, with no AI and nothing sent to third parties.
What's coming to CyberTool.dev.
Listed here so you know where this is going. None of these are live — when one ships, it moves up the page.
Subdomain Finder
Enumerate subdomains of a domain you own.
HTTP Headers Check
Grade security headers and cookie flags.
Port Scanner
Check which ports respond on your own host.
SSL / TLS Inspector
Certificate chain, expiry, protocol versions and cipher suites.
Want private repos and CI/CD?
Pro is coming. Leave your email and we will tell you first. You do not need this to start scanning today.
Scan your first repo now.
Free during beta. No credit card. Public repos, 14 languages.
