Ship secure
React Native.
A static analysis scanner that finds vulnerabilities, secrets, and misconfigurations before they reach production.
~/my-app
$
250+security rules
3.1smedian scan
100%private. Code never leaves your machine
//capabilities
Everything the audit needs.Nothing it doesn't.
Deep rule coverage
250+ rules across storage, network, crypto, auth, and platform configuration.
Zero configuration
One command, zero setup files. Works out of the box with React Native and Expo.
Dependency audit
npm audit integration flags vulnerable and deprecated packages in real time.
Fully private
Static analysis runs entirely on your machine. Code never leaves your system.
CI/CD native
Exit codes and JSON output for GitHub Actions, GitLab CI, and Jenkins.
Readable reports
Interactive HTML dashboards, JSON exports, or clean CLI output.
//detection
What it catches
The findings that fail app-store reviews, leak credentials, and end up in incident reports.
CRITHardcoded API keys & secretsTokens and credentials extractable from app bundles
CRITInsecure data storageSensitive data in AsyncStorage without encryption
CRITAndroid cleartext trafficusesCleartextTraffic allowing unencrypted HTTP
HIGHVulnerable npm packagesKnown CVEs and deprecated dependencies
HIGHUnvalidated deep linksDeep link handlers without URL validation
HIGHWebView misconfigurationsJavaScript injection and file access exposure
HIGHDisabled App Transport SecurityPermissive ATS exceptions allowing insecure HTTP
HIGHWeak authentication patternsInsecure randomness, missing JWT expiry checks
HIGHMissing root/jailbreak detectionSecurity controls bypassable on compromised devices
//coverage
Coverage,by the numbers.
250+ rules across 14 categories, spanning your code, your dependencies, and both native platforms.
Read the full rule reference01React Native & Expo
02Android security
03WebView security
04iOS security
05Storage security
06Authentication
07Network security
08Debug artifacts
09Configuration
10Cryptography
11Secrets detection
12Logging
13Manifest
14Third-party SDKs
Total rules250+
//community
Loved by developers
“"Zero setup" is the killer feature here. Security tooling is notoriously painful to configure, which is why most devs skip it until it's too late. If you can actually deliver on the "one command" promise, you aren't just selling security; you're selling time. Starred.”
“finally, peace of mind for devs”
“We identified and resolved potential security risks in our code before deploying to production, thanks to RNSec.”
“This is pretty cool! Just tried it”
“"in the age of AI and vibe coding" is the most accurate description of 2025 development i've heard. zero-setup security scanner that actually works in CI is exactly what mobile devs need when you're shipping 3x faster with claude”
“rnsec.dev is really awesome bro. Helped me a lot. Killed the huge pain point for native apps: Security. Waiting for more rules.”
“Umm thank you whoever made this.. you? This is awesome and as and indie developers I worry about stuff like this slipping through the cracks.”
“I really loved the project, thanks Adnan”
“Awesome”
“amazing!!!”
“Just tried on some of my hobby projects, and absolutely loved it!! Thanks for this Adnan, really appreciate it mann!”
“Gives me a fast security analysis of my project in just seconds. Legend @adnansahinovich. Also, vibe coders are gonna love this tool.”