Free Code Guard scan
Find the payment flaws fraudsters look for.
Code Guard runs twenty checks on your repository, built for M-Pesa, NIP, Paystack and wallet code. Each finding comes with the fix.
- Free, with no commitment
- GitHub or GitHub Enterprise
- Each finding ranked, with a fix and a test
- A prompt for your coding agent
How it works
- 01
Tell us about the repo
Which repository, which language, and where it is hosted.
- 02
We set up the scan
We agree access with your team before anything runs.
- 03
Code Guard runs 20 checks
Callbacks, races, idempotency, step-up, OTPs, secrets and more.
- 04
You get the findings
Ranked by severity, each with the exploit, the fix and a test.
What you get
Plain answers, not a sales deck.
How each flaw is exploited
In plain words, with a KES or NGN example.
The fix, for your code
Specific to your language and your payment provider.
A test that proves it
Ready to add to your CI, so it stays fixed.
A prompt for your coding agent
Paste it in and let the agent make the change.
The twenty checks
- CriticalPayment callbacks credited without checking they came from the provider
- CriticalBalance updates that can race (double spend)
- CriticalPayment or API secrets in source code
- CriticalSQL built from user input on money tables
- HighThe amount to charge taken from the client
- HighAmounts not checked to be positive
- HighPayouts without an idempotency key
- HighAccounts fetched by ID without an owner check
- HighMass assignment of balance, role or KYC fields
- HighPhone or payout details changed without re-authentication
- HighPayouts without a PIN or OTP
- HighOTP and login endpoints without a rate limit
- HighOTPs from weak randomness, or too short
- HighJWTs accepted without verification
- HighKYC checks the client can bypass
- HighTest or debug backdoors in authentication
- MediumOTPs that never expire or can be reused
- MediumMoney stored as floating point
- MediumPayouts with no amount or daily limit
- MediumCallback or redirect URLs taken from the request