security-guidance
vulnerability warnings as the code is written
first-party security review at the point of writing rather than at the point of audit — useful, and not a replacement for actual sast.
security-guidance gives pattern-based warnings on edits, runs an llm diff review on the stop hook, and does agentic commit review, with support for project-specific rules. a companion plugin, `claude-security`, does deeper vulnerability scanning at a chosen effort level entirely in-session.
catching a vulnerability as it's written is meaningfully cheaper than catching it in review, and much cheaper than catching it in production.
the description above is ours, condensed from the ranking. pricing moves — check it on the vendor's own page before you rely on it.
- category
- claude code plugins
- pricing
- free — Apache-2.0
- website
- github.com
first-party security review at the point of writing rather than at the point of audit — useful, and not a replacement for actual sast.
we researched this category against vendors' own pricing pages and licence files. that is where this line comes from — not from the vendor, and not from anything they paid for.