Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

GitHub Secret Scanning

Freemium#28 of 28 in Dependency Management SoftwareStatic Application Security Testing Sast

Detect and prevent exposed credentials in GitHub repositories.

6.0/10Editor score
GitHub Secret Scanning6.0 Visit GitHub

At a glance

  • Editor score
    6.0 / 10
  • Pricing
    Free plan · paid from $19/mo
  • Best for
    Teams preventing credential leaks
  • Free plan
    Yes
  • Paid from
    $19/mo
  • Facts checked
    20 Sep 2026
  • Where it wins

    • Scans Git history and collaboration content for exposed credentials
    • Blocks detected secrets before they reach repositories
    • Supports provider, generic, custom, and AI-detected secret patterns
  • Where it doesn't

    • Does not provide dependency management features
    • Private and internal repositories require a paid protection plan
    • Its focus is GitHub repositories and related collaboration surfaces

Our verdict on GitHub Secret Scanning

GitHub Secret Scanning detects exposed credentials such as API keys, passwords, tokens, and other secret types across GitHub repository history and selected collaboration content. It is designed for teams that need to prevent credential leaks, with scanning across all branches, issues, pull requests, discussions, wikis, and secret gists. Repository security alerts help teams identify detected leaks, while push protection can block secrets before they reach a repository.

Public repositories receive secret scanning at no cost, including secret scanning, push protection, and provider patterns. Organization-owned private and internal repositories require GitHub Secret Protection on GitHub Team or GitHub Enterprise Cloud. The published paid price is $19 per active committer per month, billed monthly. That tier adds generic patterns, validity checks, AI-detected secrets, and custom patterns. Validity checks indicate whether detected provider secrets remain active, while AI detection covers unstructured secrets such as passwords.

The product fits organizations working in GitHub that want prevention as well as post-commit detection. It supports provider patterns for services including AWS, Microsoft Azure, and Google Cloud, plus organization-specific custom regular-expression patterns for internal credentials. Teams should choose it when secret security is the priority and GitHub is the main development environment. Teams seeking dependency inventory, vulnerability tracking, or dependency update features should choose a dependency management product instead, because GitHub Secret Scanning is focused on credential protection rather than dependency management.

GitHub Secret Scanning pricing

Plans Free plan · paid from $19/moFreemium A usable free plan; paid tiers unlock the limits above. Prices re-checked Sep 2026.
See plans on github.com

All 2 GitHub Secret Scanning plans and prices →

GitHub Secret Scanning fact sheet

Free planYes
Paid from$19/mo
Ecosystem coverageNot verified
Update automationNot verified
Vulnerability alertsNot verified
License complianceNot verified
SBOM supportNot verified
Self-hosted deploymentYes
Included projectsNot verified
DeploymentCloud, Self-hosted
PlatformsWeb
SupportDocs
Built forSmall business, Mid-market, Enterprise (editorial estimate)
Integrations3 integrations: AWS, Microsoft Azure, Google Cloud
PricingFree plan · paid from $19/mo (source)
Websitegithub.com
Facts checked20 Sep 2026

GitHub Secret Scanning integrations

GitHub Secret Scanning lists 3 integrations on its own site.

  • AWS
  • Microsoft Azure
  • Google Cloud

Alternatives to GitHub Secret Scanning

See all GitHub Secret Scanning alternatives →

Also listed in

Used GitHub Secret Scanning? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used GitHub Secret Scanning for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — GitHub Secret Scanning 6.0/10

GitHub Secret Scanning is listed in our Dependency Management Software directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/github-secret-scanning/"><img src="https://www.itechguides.com/best/badge/github-secret-scanning.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes a score or a verdict. How we rank.