Permi scans your code and live applications for vulnerabilities, then uses AI to confirm which findings are real. Stop chasing false alarms. Start fixing what matters. Nigerian-specific rules no foreign scanner writes.
Most security tools do one or the other. Permi does both — from a single install, one CLI command.
Crawls pages, injects test payloads into parameters, checks security headers. Add --js for React, Vue, Angular, and Next.js SPAs using a headless Playwright browser.
permi scan --url https://yoursite.com
Reads your code, matches vulnerability patterns, catches issues before production. Works on local folders or any public GitHub repository URL.
permi scan --path ./myapp
Most scanners were built for enterprise teams in San Francisco. Permi was built for developers in Lagos, Jos, Abuja — with rules no foreign tool will ever prioritise.
Every finding is confirmed by an AI model before you see it. Real vulnerabilities surface. Noise disappears. Average noise reduction: 59% on real-world targets.
USSD gateway vulnerabilities, Paystack and Flutterwave secret key exposure, BVN/NIN pattern detection, NDPA-relevant checks. No Semgrep ruleset does this.
Scan every pull request automatically. Post findings as PR comments. Block merges on high severity findings. One line to add to your workflow.
Add --js to scan React, Vue, Angular, and Next.js apps using a headless Playwright browser. Discovers endpoints invisible to standard HTTP crawlers.
Every finding includes a Fix: line with the exact code change needed. Not a link to a blog post — the actual fix, for your language and framework.
Install for free. Use forever. The core scanner is open source. No credit card. No trial period. 50 free AI filter credits with permi setup --community.
The Permi GitHub Action runs on every PR, posts findings as comments, and blocks merges if high severity vulnerabilities are found. Free forever.
Coverage across both scan modes. Web scanning tests your running application. Source scanning catches issues before they ship.
Be first to access the VS Code extension, NDPA compliance reports, unlimited AI credits, and Pro tier features when they launch. No spam. Unsubscribe anytime.
Already installed? Give us a ⭐ on GitHub — it helps more African developers find Permi.