
Rafter
TL;DR
One-click GitHub security scanning that turns vulnerabilities, leaked secrets and weak authentication into plain-English fixes your AI coding agent can apply immediately.
Key Facts
Free version: The open-source Rafter CLI includes offline secret scanning (21+ patterns), policy enforcement and audit logs free with no account; the deep cloud analysis engine requires a license.
Pricing
Starting at $39 lifetime (Tier 1)
License Tier 1
- 15 fast scans per month
- 10 monitored sites
- All scan types & agent integrations
License Tier 2
- 50 fast scans per month
- 100 monitored sites
- Everything in Tier 1
License Tier 3
- 150 fast scans per month
- Unlimited monitored sites
- Everything in Tier 2
Additional Pricing Information
Lifetime tiers: $39 (15 fast scans/month, 10 sites), $99 (50 scans/month, 100 sites), $199 (150 scans/month, unlimited sites) — all with lifetime access and the 60-day money-back guarantee. The open-source CLI local toolkit is free without an account. Regular pricing outside the deal starts around $180 for equivalent Tier 1 value.
Details
What is Rafter?
Rafter sits where modern development actually happens: inside GitHub and inside your AI coding agent. Connect your GitHub account read-only, click once, and the cloud engine sweeps the repository for exposed secrets, XSS, SQL injection, weak authentication and risky dependencies — then hands you severity-tagged findings with exact file locations and repair snippets formatted for Claude, ChatGPT, Cursor or your IDE agent. Your code is deleted from the engine immediately after every scan. Around the scanner sits a whole workflow: a free open-source CLI for offline secret scanning and pre-commit hooks, an MCP server so agents can trigger checks themselves, a GitHub Action for CI, and live-site audits covering performance, accessibility, SEO and DNS. It was built for people shipping fast with AI assistance who never signed up to run a security stack.
Key Features
- **One-click repo scanning** — connect GitHub and scan public or private repositories from the dashboard; read-only access, code deleted after each scan.
- **AI-ready fixes** — structured findings with repair snippets you paste straight into Claude, ChatGPT, Cursor or your IDE agent.
- **Secret detection** — 21+ leak patterns via the Betterleaks engine catching exposed API keys, passwords and credentials before they ship.
- **SAST & dependency scanning** — flags XSS, SQL injection, weak auth and outdated or risky packages with severity labels.
- **Live site audits** — security plus performance, accessibility, SEO and DNS checks on any deployed website.
- **Free open-source CLI** — offline secret scanning, policy enforcement and audit logging with no account required.
- **MCP server & agent integrations** — wires into 9+ coding agents including Claude Code, Cursor, Windsurf and OpenCode.
- **CI/CD integration** — GitHub Action and API keep security checks running as code is written, not after it ships.
Who is it for?
- Solo developers and vibe-coders shipping AI-built apps fast
- Small agencies securing many client repos without hiring for security
- Teams already living in GitHub with AI coding assistants in the loop
- Founders who want cheap insurance against leaked secrets and common web vulnerabilities
Who is it NOT for?
- Teams whose code is mainly Go, Rust or Java — deep scanning is strongest on JavaScript, TypeScript and Python
- Organizations on self-hosted GitHub Enterprise — not supported
- Security teams that need enterprise-grade suites, compliance reporting or broad third-party integrations
- Developers who work strictly locally — only remote repositories are scanned
The Bottom Line
If your code ships with help from Claude, Cursor or ChatGPT, the fastest way to get burned is an API key pasted into a prompt at 1am. Rafter is the seatbelt for that workflow: one click, plain-English findings, and a fix you hand straight back to your agent. At $39 lifetime it costs less than a single month of Snyk and pays for itself the first time it catches a leaked secret. Know what you're buying — a young tool at its best on JavaScript, TypeScript and Python, with the occasional false positive to triage. For solo builders and small agencies, an easy yes while the deal lasts.
Visit website →