Pluto detects vulnerabilities in your codebase using Claude, OpenAI, or local Ollama models — before attackers do. Scan files, directories, or entire GitHub repos in seconds.
From solo devs to enterprise teams — Pluto fits right into your workflow with zero friction.
Choose Claude, OpenAI, or local Ollama models. Full flexibility with zero vendor lock-in for your security analysis workflow.
Scan single files, entire directories, or remote GitHub repositories directly from the CLI — no configuration headaches.
Get output as a beautiful PDF, structured JSON for CI/CD, clean Markdown, or colorful terminal output with severity highlighting.
Use Ollama for 100% local, offline analysis. Your code never leaves your machine — perfect for proprietary codebases.
Focus on what matters. Filter findings by CRITICAL, HIGH, MEDIUM, or LOW and cut through the noise instantly.
Drop Pluto into your pipeline with JSON output mode. Gate deployments on security findings automatically.
See how Pluto scans a real-world codebase, surfaces critical vulnerabilities, and generates a professional security report — all in under a minute.
▶ Watch Demo Video
Install from PyPI, set your API key, and start scanning. It really is that simple.
Requires Python 3.7+ and pip
Export your Anthropic or OpenAI key as an environment variable
Point Pluto at any file, directory, or GitHub repo
Every check you need across languages, frameworks, and attack surfaces.
Choose the provider that fits your privacy, cost, and performance needs.
Anthropic's Claude offers exceptional security reasoning and code understanding. The default and most accurate choice for code scanning.
Best AccuracyUse GPT-4 and GPT-4o for fast, reliable vulnerability detection. Great alternative if you're already in the OpenAI ecosystem.
Fast & ReliableRun fully offline with models like Phi, Llama, or Mistral. Your code never leaves your machine — ideal for air-gapped or sensitive environments.
100% PrivateBuilt by hackers, for hackers. Free forever. Open source on GitHub.