Horusec is a free, open-source static code analysis tool for identifying security flaws during development. It scans source code and can search project files and Git history for leaked keys and other security issues. The project describes analysis across 18 languages with 20 security tools; listed language coverage includes C#, Java, Kotlin, Python, Ruby, Golang, Terraform, JavaScript, TypeScript, Kubernetes, PHP, C, HTML, JSON, Dart, Elixir, Shell, and Nginx. Analysis can be configured through CLI resources. Developers can run Horusec from the command line, while DevSecOps teams can use it in CI/CD pipelines, and a Visual Studio Code extension is available. Horusec-Web provides vulnerability dashboards, false-positive controls, authorization tokens, and vulnerability updates. The platform integrates with the CLI to visualize and manage findings and supports native Horusec, LDAP, and Keycloak authentication. The platform repository was archived by its owner on March 19, 2025 and is read-only. Running Horusec with all its tools requires Docker; disabling Docker reduces its analysis capabilities. The platform requires RabbitMQ and PostgreSQL.
Who it is for
Horusec suits developers and DevSecOps teams seeking code analysis in development or CI/CD workflows. Its web platform may suit teams that need to visualize and manage findings, provided they account for its dependencies and archived status.
What is good
- Free and open-source under Apache License 2.0.
- Scans source code and searches Git history for leaked keys.
- Can run in CI/CD pipelines.
- Includes a Visual Studio Code extension.
- Offers vulnerability dashboards and false-positive controls.
What to know first
- Full tool use requires Docker.
- Disabling Docker reduces analysis capabilities.
- The platform repository is archived and read-only.
- The platform requires RabbitMQ and PostgreSQL.
Verdict
Horusec combines configurable static analysis with CLI, editor, and CI/CD workflows. Teams considering its web platform should note that its repository is read-only and that it requires RabbitMQ and PostgreSQL.
Horusec plans and pricing
All plansCompared on static application security testing software
- Free plan
- Yes
- Analysis target
- source
- IDE support
- Yes
- CI/CD support
- Yes
- Deployment
- self-hosted
- SCA included
- Yes
- Fix guidance
- Yes



