Secure Your Rails Applications

Brakeman is a free vulnerability scanner designed for Ruby on Rails applications. Statically analyze Rails application code to find security issues at any stage of development.

terminal
# Install Brakeman
gem install brakeman
# Scan your Rails app
brakeman
== Brakeman Report ==
# ...

Why Use Brakeman?

Fast and easy security scans built by the community

🎯

Rails-Specific

Built specifically for Ruby on Rails. Understands Rails patterns, conventions, and common vulnerability patterns.

πŸ”§

Zero Configuration

Works out of the box with sensible defaults.

πŸ”

Broad Coverage

Detects SQL injection, cross-site scripting, command injection, and dozens of other vulnerability types.

Latest News

Stay up to date with the latest releases and community contributions

Version 8.1.0

Brakeman 8.1.0

SonarQube Report Format

πŸŽ‰ What's New

  • Update SonarQube report to use generic issue format (fangxing)
  • Include regex code in validation warnings (Eliot Sykes)
  • Check validation regexes in non-activerecord models (Eliot Sykes)
  • Skip top-level vendor directory before recursive globbing (Conor O’Donnell)
Read Full Release Notes β†’