AI-Powered · Open Source · CLI Tool

Security Analysis
Supercharged
by AI

Pluto detects vulnerabilities in your codebase using Claude, OpenAI, or local Ollama models — before attackers do. Scan files, directories, or entire GitHub repos in seconds.

pluto — security scan
$ pluto scan -dir ./backend --provider claude
# Initializing Pluto AI Security Scanner...
 
🛡️ Pluto v1.0.0 | AI-Powered Code Scanner
→ Provider: claude-sonnet-4-20250514
→ Target: ./backend (23 files found)
 
⚠ [CRITICAL] SQL Injection — auth.py:142
⚠ [HIGH] Hardcoded Secret — config.py:31
⚠ [HIGH] Path Traversal — api.py:88
✓ [LOW] Missing rate limit — routes.py:204
 
✗ 3 Critical/High issues found
→ Report saved: security_report.pdf
 
$
0 Vulnerability Types
0 Languages Supported
0 AI Providers
0 Report Formats

Everything you need to
secure your codebase

From solo devs to enterprise teams — Pluto fits right into your workflow with zero friction.

🤖

Multi-Provider AI

Choose Claude, OpenAI, or local Ollama models. Full flexibility with zero vendor lock-in for your security analysis workflow.

📁

Flexible Input

Scan single files, entire directories, or remote GitHub repositories directly from the CLI — no configuration headaches.

📊

Rich Reports

Get output as a beautiful PDF, structured JSON for CI/CD, clean Markdown, or colorful terminal output with severity highlighting.

🔒

Privacy-First Mode

Use Ollama for 100% local, offline analysis. Your code never leaves your machine — perfect for proprietary codebases.

🎯

Severity Filtering

Focus on what matters. Filter findings by CRITICAL, HIGH, MEDIUM, or LOW and cut through the noise instantly.

⚡

CI/CD Ready

Drop Pluto into your pipeline with JSON output mode. Gate deployments on security findings automatically.

Watch Pluto
secure your code

See how Pluto scans a real-world codebase, surfaces critical vulnerabilities, and generates a professional security report — all in under a minute.

✓
Live scan of a vulnerable Flask app
✓
AI-generated vulnerability explanations
✓
PDF report generation in action

▶  Watch Demo Video

Up and running
in 60 seconds

Install from PyPI, set your API key, and start scanning. It really is that simple.

1

Install from PyPI

Requires Python 3.7+ and pip

2

Set your API key

Export your Anthropic or OpenAI key as an environment variable

3

Run your first scan

Point Pluto at any file, directory, or GitHub repo

bash
# Install Pluto
pip install pluto-ai
 
# Set your API key (Claude recommended)
export ANTHROPIC_API_KEY='your-key-here'
 
# Scan a file
pluto scan -code app.py
 
# Scan a directory, get PDF report
pluto scan -dir ./src --report pdf
 
# Scan a GitHub repo
pluto scan -git https://github.com/user/repo
 
# Use local Ollama (100% offline)
pluto scan -code app.py --provider ollama

Comprehensive vulnerability coverage

Every check you need across languages, frameworks, and attack surfaces.

SQL Injection
XSS / Cross-Site Scripting
Authentication Flaws
Hardcoded Secrets
Insecure Cryptography
Path Traversal
Command Injection
CSRF Vulnerabilities
Insecure Dependencies
Authorization Flaws
SSRF Vulnerabilities
Sensitive Data Exposure

Powered by the
best AI models

Choose the provider that fits your privacy, cost, and performance needs.

⚡

OpenAI

Use GPT-4 and GPT-4o for fast, reliable vulnerability detection. Great alternative if you're already in the OpenAI ecosystem.

Fast & Reliable
🏠

Ollama (Local)

Run fully offline with models like Phi, Llama, or Mistral. Your code never leaves your machine — ideal for air-gapped or sensitive environments.

100% Private

Start securing your code today

Built by hackers, for hackers. Free forever. Open source on GitHub.