Scryer is an all-in-one security auditing and static analysis tool for Ruby on Rails applications — tells you what to fix first, across security, performance, dependencies, and code quality. It scans a Ruby/Rails codebase for security vulnerabilities, performance problems, dependency risk, and code-quality issues, then ranks everything it finds by severity across all of those categories — so a scan ends with one answer to "what's most worth fixing," not four separate reports to reconcile by hand. (Style/lint is RuboCop's job — Scryer doesn't touch that, except one narrow check.) Detects SQL injection, mass assignment, SSRF, path traversal, IDOR, insecure JWT/CORS/session config, hardcoded secrets, XSS, weak crypto, and more; N+1 queries, missing pagination, and other performance heuristics; near-duplicate code; and known-vulnerable gems via a live OSV.dev dependency audit — on by default, every run. Every finding includes a human-reviewable suggested fix — never auto-applied, optionally rewritten against your actual code by any LLM you configure. Reports in JSON, self-contained HTML, CSV, or SARIF (for GitHub Code Scanning). Zero runtime dependencies beyond Ruby's own stdlib.

Required Ruby Version

>= 2.7.0

Authors

Ram Laxman Yadav

Versions

  1. 1.2.0 August 16, 2026 (173 KB)
  2. 1.1.1 August 14, 2026 (136 KB)
  3. 1.0.0 August 12, 2026 (86.5 KB)
  4. 0.3.0 August 11, 2026 (66.5 KB)
  5. 0.2.0 August 11, 2026 (65 KB)
Show all versions (7 total)

SHA 256 checksum