Installed · nothing else to configure

You're set. Open a pull request.

The next PR opened on any repository you granted access to gets audited automatically — dependencies checked against the live PyPI and npm registries, secrets and AI-specific flaws flagged inline. Findings arrive as a comment on the PR, usually in a couple of seconds. No SDK, no CI config, nothing to install locally.

What happens next

Three things, in this order.

1
Someone opens a PR. Yours or a teammate's — it does not matter who, and nobody needs an account with us.
2
A comment appears on that PR. Every added dependency resolved against the registry, every finding with its exact file and line, and the query you can reproduce with curl yourself.
3
A clean PR gets a clean comment. Silence would be indistinguishable from the app being broken, so it always reports — including what it did not analyse.
4
And if we are wrong about something, you do not have to wait for us. Reply @magaudit ignore <id> on the pull request with the id printed next to the finding, or @magaudit ignore rule <RULE-ID> for all of them. For a decision your whole team can see and review, a .magaudit.yml in the repository. And if you already use another scanner we honour its markers — pragma: allowlist secret, nosec, nosemgrep, gitleaks:allow — so you never annotate the same line twice.
Whatever your settings hide is still counted and still declared in the comment, with the reason for each one. Here is how often we get it wrong →
Private repositories

Public repos are free forever. Private ones need a plan.

Same detection engine on every tier — nothing is locked behind a higher plan. You only pay for how many private repositories it covers.

Team 5
€29/month

Up to 5 private repositories.

Subscribe →
Business 40
€149/month

Up to 40 private repositories.

Subscribe →

Reached this page directly? Subscribing still works. Email contact@magsolutionsai.com with your GitHub organisation name and we will activate the plan within one business day.

While you wait for that first PR

Two things worth five minutes.

Scan a dependency file right now — paste a requirements.txt into the scanner on the homepage. It queries PyPI live, from your browser, and shows you the same verdict the App gives on a PR.

Open the scanner →

Read what the App actually looks for — the seven gates, why CVE-based scanners miss invented packages, and what we deliberately do not claim.

Read the write-up →