detect-secrets

Also known as
detect-secrets

Available worldwide

What is detect-secrets?

An open-source security tool that scans code repositories to identify exposed secrets such as API keys, passwords, and tokens using pattern matching and heuristic filters. Designed with enterprise needs in mind, supporting custom plugins, baseline auditing, and integration with CI/CD pipelines.

Independently observed

detect-secrets pricing

We don't have detect-secrets's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Open source

Free and open source

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Self-hosted

Integrations (22)

Independently observed
  • AWS
  • Azure
  • GitHub
  • GitLab
  • Slack
  • Stripe
  • Twilio
  • SendGrid
  • Mailchimp
  • OpenAI
  • Discord
  • Telegram
  • npm
  • IBM Cloud
  • IBM Cloudant
  • Artifactory
  • Square
  • Softlayer
  • PyPI
  • Private Key detection
  • JWT Token detection
  • Basic Auth detection

Security & compliance

Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality

detect-secrets alternatives

Other secrets scanning we track, ranked by the same independent score.

All detect-secrets alternatives, ranked →

Compare detect-secrets

Side by side against other secrets scanning, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for detect-secrets, not the verdict.

Balanced composite 43 / 100
low · 28%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Price level1000.055.2
Pricing transparency550.084.6
Integrations390.093.7
Dependent projects410.062.6
Release cadence360.051.9
Stars690.031.8
Reliability00.070.0-
Capabilities00.080.0-
Development activity00.090.0
Security posture00.070.0-
Package downloads00.140.0-
Security score00.040.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d0mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars4,629highsource · 2026-08-26 · 90%
Dependent repos276highsource · 2026-08-26 · 85%

Integrations

AttributeValueEvidence
Count22mediumsource · 2026-08-19 · 60%

Language

AttributeValueEvidence
PrimaryPythonhighsource · 2026-08-26 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-26 · 95%

Market

AttributeValueEvidence
AvailabilityHqCountry: US · PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-08-19 · 75%

Pricing

AttributeValueEvidence
Price levelfreemediumsource · 2026-08-19 · 60%
TransparentYesmediumsource · 2026-08-19 · 60%
Modelcommerciallowsource · 2026-08-26 · 40%

Release

AttributeValueEvidence
Cadence days115mediumsource · 2026-08-26 · 70%
History9 itemsmediumsource · 2026-08-26 · 70%

Security

AttributeValueEvidence
VulnerabilitiesCount: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=detect-secrets&per_page=100 · Last 12m: 0highsource · 2026-08-26 · 90%