One scan, one report: security, performance, duplicate-code, and dependency audits for Ruby and Rails — the ground Brakeman, bundler-audit, Reek, and custom glue scripts usually split between them, covered by a single `scryer` command. (Style/lint is RuboCop's job — Scryer doesn't touch that.) Detects SQL injection, mass assignment, hardcoded secrets, XSS, weak crypto, and more; N+1 queries, missing pagination, and other performance heuristics; near-duplicate code; and known-vulnerable gems via a live OSV.dev dependency audit — on by default, every run. Every finding includes a human-reviewable suggested fix — never auto-applied, optionally rewritten against your actual code by any LLM you configure. Reports in JSON, self-contained HTML, or CSV. Zero runtime dependencies beyond Ruby's own stdlib.

Required Ruby Version

>= 2.7.0

Authors

Ram Laxman Yadav

Versions

  1. 1.2.1 September 04, 2026 (175 KB)
  2. 1.2.0 August 16, 2026 (173 KB)
  3. 1.1.1 August 14, 2026 (136 KB)
  4. 1.0.0 August 12, 2026 (86.5 KB)
  5. 0.3.0 August 11, 2026 (66.5 KB)
  6. 0.2.0 August 11, 2026 (65 KB)
Show all versions (8 total)

SHA 256 checksum