coderisk
Real-time SAST for VS Code, fully local & private
CodeRisk is a Visual Studio Code extension that performs static application security testing in real time as developers write code. It scans source files for common vulnerabilities such as SQL injection, cross‑site scripting, command injection and other flaw patterns, reporting findings directly within the editor. The analysis runs entirely on the local machine, without sending code to external services, and does not rely on artificial‑intelligence models or telemetry.
The tool is intended for developers who need immediate feedback on security issues while coding, especially in environments where data privacy and offline operation are required. Because it executes deterministically and locally, it can be used in isolated or regulated settings where external network calls are prohibited.
CodeRisk is positioned as an experimental, privacy‑focused alternative to cloud‑based scanners, offering a deterministic, on‑device approach to identifying security defects during the development workflow.
Reviews
Loading reviews…
Similar apps

Security & Identity
CodeSafe - Security Scanner for Founders
You vibe-code fast. We keep it secure.
Security & Identity
Mosai Scanner
Find the security holes AI vibe coding tools leave behind.

Security & Identity
XploitScan
Security scanner built for AI-generated code
Code Editors & IDEs
Complexity Indicator
Know when your code becomes unmaintainable

Security & Identity
CodeQL
Semantic code analysis engine
Security & Identity
VibeScan
Security scanner for AI-built apps - fix prompts in 30s