Qorex
Scan your codebase for quantum-vulnerable cryptography and get NIST PQC migration guidance.
Government mandates (CNSA 2.0, CMMC) require organizations to migrate away from quantum-vulnerable cryptography by 2030. Qorex finds the vulnerable code for you and tells you exactly what to replace it with.
Install
pip install qorex
Usage
# Scan a directory
qorex scan ./my-project
# Scan current directory
qorex scan
# Export full JSON report with migration guidance
qorex scan ./my-project --report json --output report.json
What it detects
| Algorithm | Risk | Threat | Replacement (NIST) |
|---|---|---|---|
| RSA | CRITICAL | Shor's algorithm | ML-KEM / ML-DSA (FIPS 203/204) |
| ECDH | CRITICAL | Shor's algorithm | ML-KEM (FIPS 203) |
| ECDSA | CRITICAL | Shor's algorithm | ML-DSA / SLH-DSA (FIPS 204/205) |
| DSA | CRITICAL | Shor's algorithm | ML-DSA (FIPS 204) |
| DH / DHE | CRITICAL | Shor's algorithm | ML-KEM (FIPS 203) |
| AES-128 | HIGH | Grover's algorithm | AES-256 (CNSA 2.0) |
| SHA-256 | HIGH | Grover's algorithm | SHA-384 / SHA-512 (CNSA 2.0) |
Languages supported: Python, C, C++, Go, Java
Example output
qorex — scanned ./my-project
Risk Algorithm File Line Match
────────── ─────────── ───────────────────────────── ────── ──────────────────────
CRITICAL RSA src/auth/keys.py 12 rsa.generate_private_key
CRITICAL ECDSA src/crypto/sign.go 34 ecdsa.Sign
HIGH SHA-256 src/utils/hash.java 8 SHA-256
3 finding(s) — run with --report json for full details and migration guidance.
JSON report
qorex scan . --report json --output report.json
Each finding includes the file, line, algorithm, risk level, plain-English explanation, NIST replacement algorithm, and migration guidance.
Roadmap
- CBOM (Cryptographic Bill of Materials) export
- CNSA 2.0 / CMMC compliance reports
- CI/CD integrations (GitHub Actions, GitLab CI)
- Tree-sitter AST scanning for C/C++
Contributing
Issues and PRs welcome. See CONTRIBUTING.md for guidelines.
License
MIT — see LICENSE.
Metadata
Release files for qorex 0.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| qorex-0.0.1.tar.gz | 9.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| qorex-0.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 23.2 kB
Release files / qorex-0.0.1.tar.gz
| Download URL | qorex-0.0.1.tar.gz |
|---|---|
| Size | 9.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7f7b9e0e69d98fd7362cb358a6d242f5443d65c5b6e5dc4af8b321491eed4f77
|
|
BLAKE2b-256 checksum How to use checksums |
e818b512833dd1ef40fbf8271e6292bfdfb3c0565ea69e2cf60186897348b5fe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 30, 2026.
Transparency logRelease files / qorex-0.0.1-py3-none-any.whl
| Download URL | qorex-0.0.1-py3-none-any.whl |
|---|---|
| Size | 13.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e515676a43049255704c682378ef8fb9846890cdf353cbf8844c21b3a2027fe9
|
|
BLAKE2b-256 checksum How to use checksums |
4a1519e6bc16816e1e714f89da265580b4db21df3e9d614741521a4259603c52
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 30, 2026.
Transparency log