Skip to main content
Plexavo

Plexavo

Plexavo interactive scan demo

Plexavo is an open-source cloud security tool that audits AWS accounts for real-world misconfigurations. It runs entirely with your own local AWS credentials, the same way you'd run aws s3 ls, so nothing about your account is ever handed to anyone else. Each scan produces a 0-100 security score and a plain-English report: what's wrong, what an attacker would actually do with it, and the exact command to fix it.

Detection is pure Python/boto3, never AI. Claude only rewrites already-found technical findings into something a non-security founder can read, and it's entirely optional. See Cost.

What it checks

32 checks across 6 categories, run against real AWS accounts:

  • IAM: privilege escalation paths, wildcard admin, cross-account trust, root usage, dormant credentials
  • Network: security groups and RDS instances exposed to the internet
  • Storage: public S3 buckets, via ACLs, bucket policies, or missing Block Public Access; buckets with no access logging configured
  • Encryption: unencrypted EBS volumes, RDS instances, S3 buckets
  • Logging: CloudTrail coverage and encryption, GuardDuty status
  • Usage: permissions granted but never used, roles nobody has assumed in 90+ days

See the docs/*-TEST-MATRIX.md files for exactly how each check was verified.

Installation

Every path below installs Plexavo into its own isolated environment.

macOS & Linux

curl -LsSf https://astral.sh/uv/install.sh | sh   # skip if you have uv
uv tool install plexavo

Prefer pipx? pipx install plexavo works the same way.

Windows

uv/pipx still work, but the launcher they put on your PATH is unsigned, and Windows Smart App Control blocks it. Run Plexavo through Python instead, two options:

Option 1, uv (recommended)

uv tool install plexavo
Set-ExecutionPolicy -Scope CurrentUser RemoteSigned
if (!(Test-Path $PROFILE)) { New-Item -ItemType File -Path $PROFILE -Force }
Add-Content $PROFILE 'function plexavo { & "$env:APPDATA\uv\tools\plexavo\Scripts\python.exe" -m plexavo @args }'

Open a new terminal. plexavo now works exactly like it does on macOS/Linux, routed through uv's signed Python instead of the blocked launcher.

Option 2, plain venv

py -m venv plexavo-venv
.\plexavo-venv\Scripts\Activate.ps1
python -m pip install plexavo
python -m plexavo

Use python -m for everything here too. The venv's own pip.exe and plexavo.exe are unsigned as well, only python.exe is signed.

AI narration (optional)

Want each finding rewritten as a full narrative? Install "plexavo[ai]" instead of plexavo, and set ANTHROPIC_API_KEY. See Cost.

Using Plexavo

Run it with no arguments and it walks you through everything: picking an AWS profile, choosing HTML or PDF, then scanning and showing your score with every finding.

plexavo             # macOS/Linux, and Windows Option 1
python -m plexavo   # Windows Option 2
Plexavo interactive CLI

The report

Reports are generated as HTML, PDF, or both. Every finding gets a free, template-based fix by default, no key, no cost. Full AI-written narration is offered automatically only when an ANTHROPIC_API_KEY is detected, see Cost.

Plexavo HTML report

Severity, confidence, and evidence are always shown as separate signals. A low-confidence Critical never reads the same as a high-confidence Medium.

Cost

Detection and the free templates always cost nothing. Live AI only runs with --explain, using your own ANTHROPIC_API_KEY in your own Anthropic account. Plexavo never sees your key and never calls the API without it. A full scan with --explain typically costs a few cents.

Contributing

git clone https://github.com/plexavo/plexavo.git
cd plexavo
uv pip install -e .

See CONTRIBUTING.md for the pattern used to add a new check.

Break Plexavo

Think you can make Plexavo miss something, or give confusing guidance? Report it. Every confirmed, genuinely new finding gets fixed and shipped, and you get a permanent credit in the Hall of Bugs. No bounty, public credit only.

Security

Found a vulnerability in the tool itself, not a misconfiguration in your own AWS account (that's the tool working correctly)? See SECURITY.md for a private reporting path.

License

AGPL-3.0, see LICENSE. Use, run, and modify it freely. If you run a modified version as a hosted service, you're required to publish those modifications too.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

plexavo-0.2.7.tar.gz (1.7 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

plexavo-0.2.7-py3-none-any.whl (1.6 MB view details)

Uploaded Python 3

File details

Details for the file plexavo-0.2.7.tar.gz.

File metadata

  • Download URL: plexavo-0.2.7.tar.gz
  • Upload date:
  • Size: 1.7 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for plexavo-0.2.7.tar.gz
Algorithm Hash digest
SHA256 7a9294b4ee1f636aa638241ffe140f22175b9ead06072046270d848762176ce7
MD5 89fdea54a35f6f4c321d6bc89d4c3c6c
BLAKE2b-256 375bd25857307d18dd4e1688f1deaecf5849c6330df4b2b9cccaf672fd1ecb6e

See more details on using hashes here.

Provenance

The following attestation bundles were made for plexavo-0.2.7.tar.gz:

Publisher: publish.yml on plexavo/Plexavo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file plexavo-0.2.7-py3-none-any.whl.

File metadata

  • Download URL: plexavo-0.2.7-py3-none-any.whl
  • Upload date:
  • Size: 1.6 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for plexavo-0.2.7-py3-none-any.whl
Algorithm Hash digest
SHA256 a3f7ef2af809a7fefa2cb95ccb35e47a1cac87c5e87a8c282d2d14678d7ffb79
MD5 b465b02bb0ac84ffaeeb7cff52997c73
BLAKE2b-256 5a57b4d088c12695606305b7f2adc29369233e4184b7294583ba75b8f52e73d1

See more details on using hashes here.

Provenance

The following attestation bundles were made for plexavo-0.2.7-py3-none-any.whl:

Publisher: publish.yml on plexavo/Plexavo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.9

2 files

0.2.8

2 files

This release

0.2.7 This release

2 files

0.2.6

2 files

0.2.5

2 files

0.2.4

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page