Scryer is an all-in-one security auditing and static analysis tool for Ruby on Rails applications — tells you what to fix first, across security, performance, dependencies, and code quality. It scans a Ruby/Rails codebase for security vulnerabilities, performance problems, dependency risk, and code-quality issues, then ranks everything it finds by severity across all of those categories — so a scan ends with one answer to "what's most worth fixing," not four separate reports to reconcile by hand. (Style/lint is RuboCop's job — Scryer doesn't touch that, except one narrow check.) Detects SQL injection, mass assignment, SSRF, path traversal, IDOR, insecure JWT/CORS/session config, hardcoded secrets, XSS, weak crypto, and more; N+1 queries, missing pagination, and other performance heuristics; near-duplicate code; and known-vulnerable gems via a live OSV.dev dependency audit — on by default, every run. Every finding includes a human-reviewable suggested fix — never auto-applied, optionally rewritten against your actual code by any LLM you configure. Reports in JSON, self-contained HTML, CSV, or SARIF (for GitHub Code Scanning). Zero runtime dependencies beyond Ruby's own stdlib.
Required Ruby Version
>= 2.7.0
Authors
Ram Laxman Yadav
Versions
- 1.2.0 August 16, 2026 (173 KB)
- 1.1.1 August 14, 2026 (136 KB)
- 1.0.0 August 12, 2026 (86.5 KB)
- 0.3.0 August 11, 2026 (66.5 KB)
- 0.2.0 August 11, 2026 (65 KB)