Security code review, all in one place.

Ziora maps every way into your app, runs the scanners security teams already trust, and keeps every finding and decision in one list. When you're ready, it briefs your AI coding agent on the fixes and checks its work.

Free during the beta · Windows, macOS and Linux · No account

checkout-service main
Files41 / 64
  • routes
  • admin.js
  • auth.js
  • invoices.js
  • webhooks.js
routes/invoices.jsJavaScript
7router.get('/invoices', requireAuth, listInvoices);
8router.get('/invoices/:id', requireAuth, getInvoice);
9router.post('/invoices', requireAuth, createInvoice);
10router.delete('/invoices/:id', deleteInvoice);
Critical

Route has no authentication

routes/invoices.js:10 · CWE-306

Suggested fix

Add requireAuth like the other routes in this file.

Interactive preview. Click around, or run the scanners.
Web and APIs
FastAPI, Flask, Django and DRF, Express, NestJS, Next.js, Fastify, Koa, Hono, Spring Boot, Laravel, Rails, ASP.NET Core, and Go with Gin, Echo, Chi, Fiber or net/http
Mobile
Flutter, Android, iOS, React Native and Capacitor

Every route, and the guard in front of it

Ziora lists every route, the guard that protects it and the risky calls behind it, including webhooks, admin pages and mobile deep links.

Then it compares each route with its neighbours. A scanner can't know which routes should need a login, but when three routes in a file require one and the fourth doesn't, Ziora flags it.

MethodPathAuthHandlerFlags
GET/invoicesrequireAuthroutes/invoices.js:7
GET/invoices/:idrequireAuthroutes/invoices.js:8
POST/invoicesrequireAuthroutes/invoices.js:9
DELETE/invoices/:idNo authroutes/invoices.js:10Unlike its siblings
GET/admin/usersrequireUserroutes/admin.js:5Weaker guard
POST/loginPublic by designroutes/auth.js:12No rate limit
POST/webhooks/stripeWebhookroutes/webhooks.js:3No signature check
GET/healthPublic by designserver/index.js:21

Showing 8 of 24 routes. Select a flagged row to see why Ziora flagged it.

From request to query, line by line

For each risky call, Ziora shows where its input came from and every line it passed through, so confirming a finding takes seconds.

When Semgrep flags the same line, the two results merge into one finding. You never triage the same bug twice.

Raw SQLShell commandsDeserializationRedirectsOutbound HTTPFile pathsTemplates
HighSQL query built from request input
Source
routes/invoices.js:13
const { status } = req.query;
Passes through
routes/invoices.js:14
const sql = `SELECT * FROM invoices WHERE status = '${status}'`;
Sink
routes/invoices.js:15 · raw SQL
const rows = db.prepare(sql).all();

Request input reaches raw SQL · found by Ziora and Semgrep

Hand the fixes to your AI coding agent

Ziora writes the brief, your agent makes the changes, and Ziora checks them. It works with Claude Code, Cursor, Copilot and Codex.

fix-plan.md5 tasks
# Security fix plan: checkout-service ## Instructions for the agentWork through the tasks in order; the most severe come first.… ## Tasks (5) ### T1. Route has no authentication, unlike its siblingsroutes/invoices.js:10 · CWE-306**Done when.** An anonymous request is rejected with 401, and a user without the right role or ownership gets 403. Legitimate callers still work. ### T2. SQL query built from request inputroutes/invoices.js:15 · CWE-89**Done when.** The query uses parameter binding or the ORM's query builder, and no request value is concatenated or interpolated into SQL.…

More than 70 built-in checks

Ziora's own analysis covers what generic scanners tend to miss: access control, data flow and framework settings. Semgrep, gitleaks and OSV-Scanner add their rules on top.

Access control

  • Routes missing the login check their siblings have
  • Routes with a weaker guard than their siblings
  • Admin routes open to anyone
  • Records fetched by ID with no login
  • Auth middleware that fails open
  • Login without rate limiting
  • Webhooks without a signature check
  • Authorization decided on the client

Injection and input

  • SQL built from request input
  • Shell commands built from user input
  • Unescaped HTML output
  • Open redirects
  • Path traversal
  • XML external entities
  • Unsafe deserialization, such as pickle

Secrets and credentials

  • API keys, tokens and passwords in code
  • Connection strings and JWT secrets
  • Hardcoded encryption keys
  • Plaintext password comparison
  • Backdoor and partial credential checks
  • Long-lived JWTs

Cryptography

  • ECB mode
  • Constant keys
  • Fast hashes used for passwords
  • Weak random numbers for security values
  • TLS certificate checks turned off

Framework settings

  • Debug mode left on in Django, Rails, Laravel and Python apps
  • CSRF protection disabled or exempted
  • Django ALLOWED_HOSTS left open
  • Exposed Spring Boot Actuator endpoints
  • Laravel mass assignment
  • Unprotected Rails engines
  • Stack traces and secrets in responses and logs

Mobile

  • Exported Android services and receivers
  • Debuggable and backup-enabled builds
  • Tapjacking and user-installed CAs
  • Cleartext traffic, missing pinning, iOS arbitrary loads
  • WebView JavaScript bridges and HTML injection
  • Tokens in plaintext storage and loose Keychain access
  • Biometric checks that fail open
  • Deep links that act without confirmation

Findings carry CWE IDs, and mobile findings are tagged with OWASP MASVS controls.

And the rest of the review

Review coverage
Mark files as reviewed as you go. A coverage ring, a per-module map and a list of high-risk files you haven't opened tell you when you're done.
Triage that sticks
Confirm a finding or dismiss it as a false positive. Findings have stable fingerprints, so your decisions survive every re-scan.
Notes and reports
Add reviewer notes to findings, then export a Markdown report with a severity summary, coverage, traces and code snippets. SARIF and GitHub issues are on the way.
Clone from a URL
Paste an HTTPS or SSH address. Ziora uses the sign-in your git already has and never asks for a password or token.
Pull without losing work
Pull the latest changes from the branch menu. Ziora re-analyses the code and keeps your triage and review marks.
A sample to learn on
Open the built-in sample, a deliberately vulnerable FastAPI app, and try every feature on real findings.

Built for code you can't share

Client work under NDA, unreleased products, regulated systems. Ziora reads your code on your own computer and never runs it.

Read the security model

Ziora never

  • Runs your codeIt reads files and parses syntax trees. Nothing from your repository is executed.
  • Opens a network portThe app and its engine talk over standard input and output.
  • Uses a shellScanners run with fixed argument lists and timeouts.
  • Shows or stores secret valuesgitleaks always runs with --redact. Fix plans and the MCP server never include them.
  • Reads outside your projectFile access is confined to the project folder, and path traversal is rejected.
  • Sends telemetryNo analytics, no tracking and no account. Ziora even runs Semgrep with its metrics turned off.

Ziora goes online only to

ActionConnects toSends
Clone or pull a repository you chooseYour git host, through your own gitWhat git sends. Ziora never sees your credentials.
Check dependencies with OSV-Scannerapi.osv.devPackage names and versions, never source code
Load Semgrep's rules, if you use Semgrepsemgrep.devA request for the default rule set. Ziora turns Semgrep's metrics and version check off.
Install a scanner, oncegithub.com for gitleaks and OSV-Scanner, pypi.org for SemgrepA download request. gitleaks and OSV-Scanner are checked against their published SHA-256 checksums before use.

Everything else, including all of Ziora's own analysis, works offline. If Semgrep can't reach its registry, Ziora gives it a built-in rule set instead.

Download Ziora

Free during the public beta · Version 0.1.0

WindowsYour system
Coming soon
macOSYour system
Coming soon
LinuxYour system
Coming soon

We are finishing the installers now. Windows comes first, then macOS and Linux.

How to verify a download

Questions

Is Ziora free?

Yes. Ziora is free during the public beta.

Does my code leave my computer?

No. Ziora reads your code locally and keeps its review notes in your project folder. It goes online only when you clone or pull a repository, when OSV-Scanner looks up your dependencies (package names and versions only), when Semgrep loads its rule set, and when you install a scanner. The security model has the details.

I'm not a security expert. Is Ziora for me?

Yes. Every finding points to the exact line and comes with a suggested fix. If you build with an AI coding agent, export the fix plan or connect the agent over MCP, then use Check fixes to confirm the work. The built-in sample project is a good place to start.

Do I need to install Semgrep, gitleaks or OSV-Scanner?

No. Ziora's own checks work without them. Ziora can download gitleaks and OSV-Scanner for you and verifies each one against its published checksum. Semgrep is optional and needs Python.

Which AI agents work with Ziora?

Any agent that can read a Markdown file can follow the fix plan. Claude Code, Cursor and Copilot can also connect over MCP to list findings, read the plan, triage and run Check fixes.