Jev in production › Code and security review

jev-attack-surface-analysis

Jev ranks codebase files and lines by vulnerability likelihood under a fixed budget. Live demo claims about one cent per repo scanned (author).

Open on GitHub ↗

about one cent per repo scannedmeasured, as published by the source
Use
Code and security review
Industry
Security
Form
Open-source tool
Stage
Beta
Listed
2026-10-03
Found via
github
Repository
franciscocarloserra/jev-attack-surface-analysis
Stars
2
Forks
0
Last push
2026-10-02
Language
Python
License
none stated

The README opens with

Maps the attack surface of a backend codebase and flags likely vulnerabilities, down to the suspicious line, for about one cent per repo.

Try it without installing anything: https://franciscocarloserra.github.io/jev-attack-surface-analysis/ (read-only results on PyGoat and NodeGoat).

You give it a repo (Python, JavaScript or TypeScript) and a budget in dollars. You get:

- a map of the codebase, one block per file, colored by how suspicious it is; - a ranked list of potential vulnerabilities, each pointing to the exact line (e.g. user input reaching SQL, eval, a shell or an outbound request); - a copy button (or printissues.py) that hands that list to an AI agent, with the instruction to validate each issue, not to fix it.

Badge

For the project's own README, linking back here:

Listed in Jev in production

Also used for code and security review