Security code review, all in one place.
Ziora maps every way into your app, runs the scanners security teams already trust, and keeps every finding and decision in one list. When you're ready, it briefs your AI coding agent on the fixes and checks its work.
- routes
- admin.js
- auth.js
- invoices.js
- webhooks.js
routes/invoices.jsJavaScriptRoute has no authentication
routes/invoices.js:10 · CWE-306
Suggested fix
Add requireAuth like the other routes in this file.
- Web and APIs
- FastAPI, Flask, Django and DRF, Express, NestJS, Next.js, Fastify, Koa, Hono, Spring Boot, Laravel, Rails, ASP.NET Core, and Go with Gin, Echo, Chi, Fiber or net/http
- Mobile
- Flutter, Android, iOS, React Native and Capacitor
Every route, and the guard in front of it
Ziora lists every route, the guard that protects it and the risky calls behind it, including webhooks, admin pages and mobile deep links.
Then it compares each route with its neighbours. A scanner can't know which routes should need a login, but when three routes in a file require one and the fourth doesn't, Ziora flags it.
| Method | Path | Auth | Handler | Flags |
|---|---|---|---|---|
| GET | /invoices | requireAuth | routes/invoices.js:7 | |
| GET | /invoices/:id | requireAuth | routes/invoices.js:8 | |
| POST | /invoices | requireAuth | routes/invoices.js:9 | |
| DELETE | /invoices/:id | No auth | routes/invoices.js:10 | Unlike its siblings |
| GET | /admin/users | requireUser | routes/admin.js:5 | Weaker guard |
| POST | /login | Public by design | routes/auth.js:12 | No rate limit |
| POST | /webhooks/stripe | Webhook | routes/webhooks.js:3 | No signature check |
| GET | /health | Public by design | server/index.js:21 |
Showing 8 of 24 routes. Select a flagged row to see why Ziora flagged it.
From request to query, line by line
For each risky call, Ziora shows where its input came from and every line it passed through, so confirming a finding takes seconds.
When Semgrep flags the same line, the two results merge into one finding. You never triage the same bug twice.
const { status } = req.query;
const sql = `SELECT * FROM invoices WHERE status = '${status}'`;
const rows = db.prepare(sql).all();
Request input reaches raw SQL · found by Ziora and Semgrep
Fixed · no request value reaches raw SQL
Hand the fixes to your AI coding agent
Ziora writes the brief, your agent makes the changes, and Ziora checks them. It works with Claude Code, Cursor, Copilot and Codex.
fix-plan.md5 tasks# Security fix plan: checkout-service ## Instructions for the agentWork through the tasks in order; the most severe come first.… ## Tasks (5) ### T1. Route has no authentication, unlike its siblingsroutes/invoices.js:10 · CWE-306**Done when.** An anonymous request is rejected with 401, and a user without the right role or ownership gets 403. Legitimate callers still work. ### T2. SQL query built from request inputroutes/invoices.js:15 · CWE-89**Done when.** The query uses parameter binding or the ORM's query builder, and no request value is concatenated or interpolated into SQL.…
Check fixes
Compares the code now with the plan you gave your agent.
More than 70 built-in checks
Ziora's own analysis covers what generic scanners tend to miss: access control, data flow and framework settings. Semgrep, gitleaks and OSV-Scanner add their rules on top.
Access control
- Routes missing the login check their siblings have
- Routes with a weaker guard than their siblings
- Admin routes open to anyone
- Records fetched by ID with no login
- Auth middleware that fails open
- Login without rate limiting
- Webhooks without a signature check
- Authorization decided on the client
Injection and input
- SQL built from request input
- Shell commands built from user input
- Unescaped HTML output
- Open redirects
- Path traversal
- XML external entities
- Unsafe deserialization, such as pickle
Secrets and credentials
- API keys, tokens and passwords in code
- Connection strings and JWT secrets
- Hardcoded encryption keys
- Plaintext password comparison
- Backdoor and partial credential checks
- Long-lived JWTs
Cryptography
- ECB mode
- Constant keys
- Fast hashes used for passwords
- Weak random numbers for security values
- TLS certificate checks turned off
Framework settings
- Debug mode left on in Django, Rails, Laravel and Python apps
- CSRF protection disabled or exempted
- Django ALLOWED_HOSTS left open
- Exposed Spring Boot Actuator endpoints
- Laravel mass assignment
- Unprotected Rails engines
- Stack traces and secrets in responses and logs
Mobile
- Exported Android services and receivers
- Debuggable and backup-enabled builds
- Tapjacking and user-installed CAs
- Cleartext traffic, missing pinning, iOS arbitrary loads
- WebView JavaScript bridges and HTML injection
- Tokens in plaintext storage and loose Keychain access
- Biometric checks that fail open
- Deep links that act without confirmation
No built-in check matches that. Semgrep's rules may still cover it.
Findings carry CWE IDs, and mobile findings are tagged with OWASP MASVS controls.
And the rest of the review
- Review coverage
- Mark files as reviewed as you go. A coverage ring, a per-module map and a list of high-risk files you haven't opened tell you when you're done.
- Triage that sticks
- Confirm a finding or dismiss it as a false positive. Findings have stable fingerprints, so your decisions survive every re-scan.
- Notes and reports
- Add reviewer notes to findings, then export a Markdown report with a severity summary, coverage, traces and code snippets. SARIF and GitHub issues are on the way.
- Clone from a URL
- Paste an HTTPS or SSH address. Ziora uses the sign-in your git already has and never asks for a password or token.
- Pull without losing work
- Pull the latest changes from the branch menu. Ziora re-analyses the code and keeps your triage and review marks.
- A sample to learn on
- Open the built-in sample, a deliberately vulnerable FastAPI app, and try every feature on real findings.
Built for code you can't share
Client work under NDA, unreleased products, regulated systems. Ziora reads your code on your own computer and never runs it.
Read the security modelZiora never
- Runs your codeIt reads files and parses syntax trees. Nothing from your repository is executed.
- Opens a network portThe app and its engine talk over standard input and output.
- Uses a shellScanners run with fixed argument lists and timeouts.
- Shows or stores secret valuesgitleaks always runs with
--redact. Fix plans and the MCP server never include them. - Reads outside your projectFile access is confined to the project folder, and path traversal is rejected.
- Sends telemetryNo analytics, no tracking and no account. Ziora even runs Semgrep with its metrics turned off.
Ziora goes online only to
| Action | Connects to | Sends |
|---|---|---|
| Clone or pull a repository you choose | Your git host, through your own git | What git sends. Ziora never sees your credentials. |
| Check dependencies with OSV-Scanner | api.osv.dev | Package names and versions, never source code |
| Load Semgrep's rules, if you use Semgrep | semgrep.dev | A request for the default rule set. Ziora turns Semgrep's metrics and version check off. |
| Install a scanner, once | github.com for gitleaks and OSV-Scanner, pypi.org for Semgrep | A download request. gitleaks and OSV-Scanner are checked against their published SHA-256 checksums before use. |
Everything else, including all of Ziora's own analysis, works offline. If Semgrep can't reach its registry, Ziora gives it a built-in rule set instead.
Download Ziora
Free during the public beta · Version 0.1.0
We are finishing the installers now. Windows comes first, then macOS and Linux.
How to verify a downloadZiora is a desktop app. Open this page on your computer to download it.
Questions
Is Ziora free?
Yes. Ziora is free during the public beta.
Does my code leave my computer?
No. Ziora reads your code locally and keeps its review notes in your project folder. It goes online only when you clone or pull a repository, when OSV-Scanner looks up your dependencies (package names and versions only), when Semgrep loads its rule set, and when you install a scanner. The security model has the details.
I'm not a security expert. Is Ziora for me?
Yes. Every finding points to the exact line and comes with a suggested fix. If you build with an AI coding agent, export the fix plan or connect the agent over MCP, then use Check fixes to confirm the work. The built-in sample project is a good place to start.
Do I need to install Semgrep, gitleaks or OSV-Scanner?
No. Ziora's own checks work without them. Ziora can download gitleaks and OSV-Scanner for you and verifies each one against its published checksum. Semgrep is optional and needs Python.
Which AI agents work with Ziora?
Any agent that can read a Markdown file can follow the fix plan. Claude Code, Cursor and Copilot can also connect over MCP to list findings, read the plan, triage and run Check fixes.