Free public scan

Get a CRA Readiness Snapshot before it becomes a surprise.

Point Threadcairn at one public GitHub repository. Get the bounded dependency inventory, vulnerability coverage, and potential CRA-relevant signals that deserve a human review.

Public repositories only. We read public metadata, bounded tree entries, and supported dependency manifests. We do not clone or retain source files or raw inputs; bounded scan evidence is retained for this repository.

No account required • Read-only analysis • Nothing modified.

The scan does not retain source files or raw inputs. Bounded dependency and vulnerability evidence is retained for this repository, while anonymous aggregate funnel events remain free of repository URLs, source content, credentials, and customer-identifying data.

01 / bounded

Read only what matters.

The first pass reads public repository metadata, bounded tree entries, and supported dependency manifests from the default branch.

02 / normalized

Useful, not overclaimed.

Exact package versions become a normalized in-memory component inventory. Raw scan inputs and results are not persisted; only anonymous aggregate funnel events are.

03 / honest

Coverage stays visible.

Rate limits, truncation, and unavailable vulnerability lookups remain visible instead of becoming false confidence or a legal conclusion.