Horusec

Web · Windows · Mac · Linux · Self-hosted · API · Extension

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

Horusec is a free, open-source static code analysis tool for identifying security flaws during development. It scans source code and can search project files and Git history for leaked keys and other security issues. The project describes analysis across 18 languages with 20 security tools; listed language coverage includes C#, Java, Kotlin, Python, Ruby, Golang, Terraform, JavaScript, TypeScript, Kubernetes, PHP, C, HTML, JSON, Dart, Elixir, Shell, and Nginx. Analysis can be configured through CLI resources. Developers can run Horusec from the command line, while DevSecOps teams can use it in CI/CD pipelines, and a Visual Studio Code extension is available. Horusec-Web provides vulnerability dashboards, false-positive controls, authorization tokens, and vulnerability updates. The platform integrates with the CLI to visualize and manage findings and supports native Horusec, LDAP, and Keycloak authentication. The platform repository was archived by its owner on March 19, 2025 and is read-only. Running Horusec with all its tools requires Docker; disabling Docker reduces its analysis capabilities. The platform requires RabbitMQ and PostgreSQL.

Who it is for

Horusec suits developers and DevSecOps teams seeking code analysis in development or CI/CD workflows. Its web platform may suit teams that need to visualize and manage findings, provided they account for its dependencies and archived status.

What is good

  • Free and open-source under Apache License 2.0.
  • Scans source code and searches Git history for leaked keys.
  • Can run in CI/CD pipelines.
  • Includes a Visual Studio Code extension.
  • Offers vulnerability dashboards and false-positive controls.

What to know first

  • Full tool use requires Docker.
  • Disabling Docker reduces analysis capabilities.
  • The platform repository is archived and read-only.
  • The platform requires RabbitMQ and PostgreSQL.

Verdict

Horusec combines configurable static analysis with CLI, editor, and CI/CD workflows. Teams considering its web platform should note that its repository is read-only and that it requires RabbitMQ and PostgreSQL.

Horusec plans and pricing

All plans
Open source Free Apache License 2.0 · CLI and platform components github.com · 1 Oct 2026

Compared on static application security testing software

Free plan
Yes
Analysis target
source
IDE support
Yes
CI/CD support
Yes
Deployment
self-hosted
SCA included
Yes
Fix guidance
Yes

Best Horusec alternatives

See all 12