Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

OWASP IDE-VulScanner

Free#21 of 21 in IDE Code Security Plugins

Open-source IDE plugin for scanning application components for vulnerabilities.

—Not yet scored
OWASP IDE-VulScanner— Visit OWASP

At a glance

  • Editor score
    Not yet scored
  • Pricing
    Free plan
  • Best for
    Developers needing free dependency checks in IDEs
  • Free plan
    Yes
  • Paid from
    None
  • IDE coverage
    Broad
  • Facts checked
    26 Sep 2026
  • Where it wins

    • Scans third-party dependencies with OWASP Dependency-Check
    • Runs vulnerability scans during implementation inside the IDE
    • Supports Eclipse, IntelliJ, and Visual Studio Code
  • Where it doesn't

    • Focuses on dependency and source-code security, not general code quality
    • Broader SAST and AI remediation capabilities are documented for VS Code
    • No broader integration details are provided

Our verdict on OWASP IDE-VulScanner

OWASP IDE-VulScanner is an open-source IDE plugin for developers who want vulnerability checks while implementing software. It uses OWASP Dependency-Check to scan third-party application dependencies and presents vulnerable dependencies with recommended fixes. Plugins are documented for Eclipse, IntelliJ, and Visual Studio Code, making it relevant to teams working across those editors who want security feedback in their development environment.

Its clearest strength is the dependency-scanning workflow: the tool brings checks for known vulnerabilities in third-party components into the IDE rather than limiting them to a separate review step. The documented scope is dependency and source-code security scanning, not general-purpose code quality analysis. A current Visual Studio Code extension listing also describes static application security testing and local AI-assisted remediation; those additional capabilities are specifically described for the VS Code extension, so teams should not assume the same breadth across every supported editor. Developers looking primarily for dependency checks may find the focused scope a good fit, while those seeking a wider code quality suite should consider alternatives.

OWASP IDE-VulScanner is free and open source, so it suits developers seeking an accessible IDE-based security check without a paid-plan decision. Its editor coverage spans Eclipse, IntelliJ, and VS Code, but broader integration information is not part of its documented positioning. Teams should weigh whether this editor-centered workflow covers their needs, especially if they require wider ecosystem connections or consistent capabilities across multiple IDEs. Choose it for in-IDE dependency vulnerability scanning; look elsewhere if a broad security or code quality platform is the priority.

OWASP IDE-VulScanner pricing

Plans Free planFree Free to use — no paid tier required for the core job.
See plans on owasp.github.io

OWASP IDE-VulScanner fact sheet

Free planYes
Paid fromNone
IDE coverageBroad
Security analysisYes
Taint analysisNot verified
Code quality checksNot verified
In-IDE fixesYes
Languages supportedNot verified
PricingFree plan
Websiteowasp.github.io
Facts checked26 Sep 2026

Alternatives to OWASP IDE-VulScanner

See all OWASP IDE-VulScanner alternatives →

Used OWASP IDE-VulScanner? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used OWASP IDE-VulScanner for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — OWASP IDE-VulScanner —/10

OWASP IDE-VulScanner is listed in our IDE Code Security Plugins directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/owasp-ide-vulscanner/"><img src="https://www.itechguides.com/best/badge/owasp-ide-vulscanner.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes a score or a verdict. How we rank.