GitHub repository
Analyse a public repository or an authorised private repository through the managed runner.
MaxiCyber analyses application code as a connected system—not a list of isolated patterns. See how data moves, where controls break, which dependencies matter, and what developers should fix first.
Select each stage to see how MaxiCyber turns source code into evidence developers can act on and leadership can prioritise.
Authorise a GitHub repository or choose a controlled CLI/source-handling mode.
Select the workflow and source-handling model that fits the repository and your data policy.
Analyse a public repository or an authorised private repository through the managed runner.
Run a full-workspace scan or inspect only current Git changes from the CyberWL Agent extension.
Choose local findings upload, a sanitised cloud snapshot, or deployment-gated deep analysis.
The Visual Studio Code extension exposes security, functional-quality, and performance/scalability checks. Managed analysis adds deeper repository context and evidence-backed reporting.
Switch between an illustrative developer finding, its architecture context, and the executive view. Actual reports link these views to the same evidence.
A route queries a project by user-controlled ID without including the current organisation in the database predicate. An authenticated user could request another tenant's project if an identifier is discovered.
Scope the query by project ID and authenticated organisation ID, then return the same not-found response for inaccessible records.
Add a cross-tenant integration test and verify direct object requests cannot disclose record existence.
Choose repository, branch, analysis areas, and approved source-handling mode.
The managed runner performs static, read-only review and package inspection.
Engineering and security confirm priority, ownership, and remediation sequence.
Rerun analysis and retain a durable report for technical and executive stakeholders.