verifier.org

security-guidance

vulnerability warnings as the code is written

free — Apache-2.0#catching-security-mistak

first-party security review at the point of writing rather than at the point of audit — useful, and not a replacement for actual sast.

security-guidance gives pattern-based warnings on edits, runs an llm diff review on the stop hook, and does agentic commit review, with support for project-specific rules. a companion plugin, `claude-security`, does deeper vulnerability scanning at a chosen effort level entirely in-session.

catching a vulnerability as it's written is meaningfully cheaper than catching it in review, and much cheaper than catching it in production.

the description above is ours, condensed from the ranking. pricing moves — check it on the vendor's own page before you rely on it.

pricing
free — Apache-2.0
website
github.com
our verdict

first-party security review at the point of writing rather than at the point of audit — useful, and not a replacement for actual sast.

we researched this category against vendors' own pricing pages and licence files. that is where this line comes from — not from the vendor, and not from anything they paid for.

more claude code plugins

claudekit

hooks, subagents and commands packaged as one installable toolkit

#hooks#toolkit

ccstatusline

configurable status line showing model, context use and session cost

#statusline

ccusage

reads local session files to report token use and cost per project

#usage#cost

frontend-design

we checked thisfree — Apache-2.0

the single most-installed plugin there is

#anyone-generating-ui-who