Current CodeRiskTools Architecture
MCPwatch Exposure Ledger withdrawn from public sale; existing buyer access retained.
Layer 1: Scanner 3.0.0
CodeRiskTools Scanner 3.0.0 is an MIT-licensed GitHub project for local secret and configuration-change review. It is free to inspect, fork, and run.
Layer 2: Developer Safety Kit
The retired Developer Safety Kit remains available to existing buyers and includes the retired Basic, Workflow, WordPress QA, Gumroad QA, scanner, and related practical modules. Those retired modules are not sold as standalone products.
Layer 3: MCPwatch
See the current CodeRiskTools catalog for available products.
Layer 4: AI Change Firewall
AI Change Firewall remains separate from the retired CodeRiskTools module pages. Firewall Professional is available for $19 and Firewall Agency for $30 as one-time purchases.
How to choose
Use the free Scanner 3.0.0 project for source-visible local checks. Use the Developer Safety Kit when you want the retired practical templates in one current package. Use MCPwatch Exposure Ledger for offline MCP evidence review. Compare Snyk, GitGuardian, SonarQube, Semgrep, TruffleHog, and Gitleaks for broader platform needs. Expert Audit intake is paused and CodeRiskTools is not accepting new private code audit orders; do not send private repositories, credentials, or archives.
| Current option | Status | Price | Best fit |
|---|---|---|---|
| Scanner 3.0.0 | Published source-visible scanner | MIT/free on GitHub | Local secret and configuration-change review |
| Retired offer | Developer Safety Kit withdrawn from public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. |
| Retired offer | MCPwatch Exposure Ledger withdrawn from public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. |
| Retired offer | MCPwatch Exposure Ledger withdrawn from public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. |
| MCPwatch Scanner / Scanner Starter | Development/unpublished | No public scanner checkout | Scanner and Scanner Starter are unpublished; Exposure Ledger Professional/Agency are legacy buyer-access materials |
| AI Change Firewall Professional | Available | $19 one-time | Change-risk review for individual operators |
| AI Change Firewall Agency | Available | $30 one-time | Agency/team delivery workflows |
| Expert Audit | Paused | No orders | CodeRiskTools is not accepting new private code audit orders |
Honest Limitations
Scanner 3.0.0 runs its documented secret and configuration-change checks locally without uploading source code to CodeRiskTools. Safety Kit materials are downloadable; purchase, delivery, updates, support, and optional integrations use online services. These products reduce review risk but do not guarantee security or replace human judgment and professional assessment.
This retired module is now handled through the Safety Kit retired — current catalog is retained as legacy buyer-access material; there is no standalone sale for the retired module.
The retired module combinations are now handled by the Developer Safety Kit. Use Scanner 3.0.0 when you only need source-visible local scanning; use Firewall Professional or Agency when you need the separate firewall product.
Compare CodeRiskTools with Alternatives
Current CodeRiskTools availability is Scanner MIT/free, Safety Kit legacy buyer-access material, paid Firewall available at $19 Professional / $30 Agency, and See the current CodeRiskTools catalog for available products.
Frequently Asked Questions
Is CodeRiskTools a SaaS platform? Do I need to upload my code?
CodeRiskTools includes downloadable CLI tools, checklists, and workflow templates. Packaged tools run their documented core workflows on your machine without uploading source code to CodeRiskTools. Purchase, download, updates, support, and optional integrations use online services.
How is this different from Snyk or SonarQube?
Snyk and SonarQube are enterprise SaaS platforms with per-developer monthly subscriptions (starting at $25/developer/month for Snyk Team, $750/year for SonarQube Developer). For current offers, use Scanner 3.0.0 for free local scanning, the Safety Kit legacy buyer-access material, paid Firewall available at $19 Professional / $30 Agency, or Exposure Ledger editions are legacy buyer-access materials. No recurring billing, no code upload, no per-seat pricing. CodeRiskTools covers AI code review, secret scanning, and deployment QA — the specific gaps that emerge when developers use AI coding agents like Copilot, Cursor, and Claude.
Does the Scanner 3.0.0 replace GitGuardian?
GitGuardian is a cloud-based platform focused on secrets detection across your entire git history and CI/CD pipelines (starting at free for up to 25 developers, then $18/developer/month). The CodeRiskTools Scanner 3.0.0 is a local CLI that scans specific diffs — perfect for pre-merge checks of AI-generated code. They complement each other: use GitGuardian for organization-wide secret scanning, and use the Scanner 3.0.0 for fast local checks before you merge AI-generated changes.
Can I use CodeRiskTools on Windows?
The CLI tools (Scanner 3.0.0, WordPress Launch & Rollback QA Kit, Gumroad Product Launch QA Kit) are Python scripts that work on any platform with Python 3.10+. The checklists and workflow templates are Markdown files that work everywhere.
What if I’m not happy with my purchase?
Contact us via the contact page and we’ll work it out. CodeRiskTools products are practical tools with real, documented outputs — if the tool doesn’t do what the product page says it does, you shouldn’t pay for it.
Can the Scanner 3.0.0 detect leaked API keys after a package update?
Yes. The Scanner 3.0.0 scans any unified diff for 50+ secret patterns including AWS keys, Stripe keys, GitHub tokens, database URLs, and private keys. If an npm package update or dependency change introduces secrets or config drift, the scanner catches it in the diff — before you merge.
Do I need CI/CD to use these tools?
No. All CodeRiskTools products work as local CLI tools and checklists. The CLI tools also include CI/pre-commit hook examples for teams that want automated checks, but you can run them manually on any diff. The checklists and workflow templates work with any process — pen and paper, GitHub PRs, GitLab MRs, or local terminal.
Current resources
Scanner 3.0.0 is the public scanner. The See the current CodeRiskTools catalog for available products.
Setup Time and Experience Level
| Resource | Setup Time | Experience Level | Python Required |
|---|---|---|---|
| Scanner 3.0.0 | 2-5 minutes | Beginner to intermediate | Yes |
| Retired offer | Developer Safety Kit withdrawn from public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. | Not for public sale; existing buyer access retained. |
| See the current CodeRiskTools catalog for available products. | 10-15 minutes | Intermediate | No Python installation required |
| See the current CodeRiskTools catalog for available products. | 15-20 minutes | Intermediate | No Python installation required |
| MCPwatch Scanner / Scanner Starter | Not publicly available | Development/unpublished | Not applicable |
| AI Change Firewall Professional | 5-10 minutes | Intermediate | See product documentation |
| AI Change Firewall Agency | 10-15 minutes | Intermediate | See product documentation |
| Expert Audit | Paused | Not accepting new private code | Not applicable |
FAQ
- Which CodeRiskTools resource should I start with?
- Start with Scanner 3.0.0 if you need local secret and configuration-change review. Use the Developer Safety Kit when you want the retired checklists, workflows, and deployment QA material in one current package.
- Does any current resource upload my code to CodeRiskTools?
- Scanner 3.0.0 runs locally for its documented core workflow. Purchase, download, updates, support, and optional integrations may still use online services.
- What happened to Basic, Pro, Agency, Workflow, WordPress, Gumroad, and Client Delivery kits?
- Those standalone module pages are retired. The practical materials are included in the Safety Kit retired — current catalog is retained as legacy buyer-access material.
- Is Expert Audit available?
- No. Expert Audit intake is paused. CodeRiskTools is not accepting new private code audit orders and no turnaround is promised.
- How is this different from Snyk, GitGuardian, or SonarQube?
- Snyk, GitGuardian, and SonarQube are broader security platforms. CodeRiskTools focuses on local AI-code review workflows, current Scanner 3.0.0 checks, and practical safety materials for small teams.
Learn More
- Compare CodeRiskTools vs Snyk, GitGuardian, Semgrep, and SonarQube — Full feature and pricing comparison for all major alternatives.
- AI Code Security Guide — The four key areas of AI code security and practical steps for safer coding.
- Safety Kit retired — current catalog — Download and start reviewing AI code in 2 minutes.
System Requirements
Packaged CodeRiskTools kits run their documented core workflows on your machine without requiring a CodeRiskTools cloud account or source-code upload. Purchase, download, updates, support, and optional integrations remain online activities.
| Requirement | Details |
|---|---|
| Python | 3.8+ (most kits include a CLI that runs on Python 3.8 or later) |
| Operating System | macOS, Linux, or Windows with WSL |
| Internet | Only needed to download the kit. Scanning and reviews run 100% offline. |
| Git | Required for diff-based scanning (Scanner 3.0.0, Pro Kit, Workflow Pack) |
| Setup Time | Under 5 minutes for all kits. Download, unzip, run. |
| Data Privacy | Packaged tools do not upload source code to CodeRiskTools during their documented core workflows. Purchase, download, updates, support, and optional integrations use online services. |
Not sure where to start?
The retired 5-Point AI Code Review Checklist is no longer available through a public checkout; existing buyers retain access.