Skip to main content

Vigilo

CI Python 3.10+ License: MIT PyPI version

Vigilo is a fast, zero-configuration static security scanner for Python, JavaScript, and TypeScript (Node.js & React). It detects exploitable vulnerability patterns (CWEs) in first-party code using AST traversal combined with local data-flow analysis to minimize false positives.

Runs across Linux, macOS, and Windows — either via pip or as a standalone binary with no Python installation required.


Supported Languages

Language / Framework Status File Extensions Engine
Python Stable .py Native Python AST + Data Flow
JavaScript New in v0.3.0 .js, .mjs, .cjs, .jsx Tree-Sitter (tree-sitter-javascript)
TypeScript / React New in v0.3.0 .ts, .tsx Tree-Sitter (tree-sitter-typescript)

See ROADMAP.md for planned languages (Java, HTML, CSS).


Why Vigilo?

  • High-Signal over High-Noise: Traditional linters flag safe string constants and standard library calls indiscriminately. Vigilo uses local data-flow analysis to distinguish harmless constants from untrusted dynamic inputs.
  • Zero Configuration: Drop it directly into your workflow or CI pipeline with vigilo scan . or vigilo .. No YAML rule authoring or database setup required.
  • No Node.js Runtime Required: Multi-language parsing is powered by embeddable Tree-Sitter grammars compiled to native libraries — you do not need Node.js installed to scan JS/TS/React codebases.
  • First-Party Code Focus: While tools like pip-audit scan third-party dependencies for CVEs, Vigilo scans your code for logic and injection flaws.

Installation & Quickstart

Option A: Install via PyPI (Python 3.10+)

pip install vigilo

Option B: Standalone Executable (No Python Required)

Pre-built standalone single-file executables are available for Linux, macOS, and Windows on the Releases Page:

  • Linux (x86_64): vigilo-linux-x86_64
  • macOS: vigilo-macos
  • Windows (x86_64): vigilo-windows-x86_64.exe

Verifying Checksums

Every release includes a SHA256SUMS.txt file to verify binary integrity:

# Verify checksum on Linux/macOS
sha256sum -c SHA256SUMS.txt

Note on Antivirus Alerts: Standalone executables are bundled with PyInstaller. Some heuristic antivirus engines or Windows SmartScreen may occasionally flag newly published PyInstaller binaries as unfamiliar. This is a known false positive with packed binaries. You can verify the integrity using the SHA256 checksum or install via pip install vigilo to run from source.


Usage

Scan the current directory:

vigilo scan .

Or use the shortcut alias:

vigilo .

Generate structured JSON output for CI/CD pipelines:

vigilo scan . --format json

Filter by minimum severity:

vigilo scan . --min-severity high

Include code correctness diagnostics (syntax errors, undefined names, unclosed resources):

vigilo scan . --correctness
# or run the dedicated diagnose subcommand:
vigilo diagnose .

Exclude specific directories or glob patterns:

vigilo scan . --exclude "tests/*" --exclude "migrations/*"

Python API

from vigilo import scan

# Security scan (default)
findings = scan("src/")

# Security + Correctness scan
all_findings = scan("src/", include_correctness=True)

for finding in findings:
    print(
        f"[{finding.severity.upper()}] {finding.detector.id} {finding.detector.name} ({finding.detector.category})"
    )
    print(f"  Location: {finding.location}")
    print(f"  Fix: {finding.fix_hint}")

Supported Detectors

Python Security Vulnerabilities

ID CWE Vulnerability Severity Target APIs
VIGILO-001 CWE-89 SQL Injection HIGH db.execute(), cursor.execute(), text(), raw()
VIGILO-002 CWE-78 OS Command Injection HIGH subprocess.*(shell=True), os.system(), os.popen()
VIGILO-003 CWE-94 Code Injection HIGH eval(), exec(), compile()
VIGILO-004 CWE-502 Unsafe Deserialization HIGH pickle.loads(), yaml.load(), marshal.loads()
VIGILO-005 CWE-22 Path Traversal HIGH open(), os.open(), io.open()

JavaScript / TypeScript / React Security Detectors (New in v0.3.0)

ID CWE Vulnerability Severity Target Patterns / APIs
VIGILO-JS-001 CWE-79 Cross-Site Scripting (XSS) HIGH innerHTML/outerHTML, document.write(), React dangerouslySetInnerHTML
VIGILO-JS-002 CWE-94 Code Injection HIGH eval(), new Function(), string-based setTimeout/setInterval
VIGILO-JS-003 CWE-78 OS Command Injection HIGH child_process.exec(), execSync(), spawn() with shell: true
VIGILO-JS-004 CWE-1321 Prototype Pollution HIGH __proto__, constructor.prototype direct mutation, unsafe deep merge
VIGILO-JS-005 CWE-798 Hardcoded Secrets & Credentials HIGH AWS keys, GitHub PATs, Slack tokens, JWTs, DB connection strings

Python Code Correctness Diagnostics (Opt-In with --correctness or diagnose)

ID Issue Severity Description
VIGILO-C01 Syntax & Indentation Error HIGH Python parse failure or bad indentation
VIGILO-C02 Undefined Name Usage MEDIUM Use of unbound or misspelled variable/name
VIGILO-C03 Unused Import / Variable LOW Unused imported module or assigned local variable
VIGILO-C04 Unclosed File Resource MEDIUM Raw open() call without context manager (with)
VIGILO-C05 Bare Except Clause MEDIUM Blanket except: catch masking critical errors

CLI Reference

usage: vigilo [-h] [--version] {scan,diagnose} ... [target] [--format {text,json}]
              [--min-severity {low,medium,high}] [--exclude EXCLUDE] [--correctness]
              [--no-color]

Commands:
  scan                  Scan target directory or file for security vulnerabilities
  diagnose              Run code correctness diagnostics (syntax, undefined names, resources)

Options:
  target                Directory or file to scan (default: '.')
  --format, -f          Output report format: 'text' or 'json' (default: 'text')
  --min-severity, -s    Minimum severity threshold: 'low', 'medium', 'high' (default: 'low')
  --correctness, -c     Include code correctness diagnostics alongside security checks
  --exclude, -e         Exclude path matching glob pattern (repeatable)
  --no-color            Disable ANSI terminal coloring
  --version, -V         Show version and exit
  --help, -h            Show help and exit

Exit Codes

Code Meaning
0 Clean — no vulnerabilities found at or above --min-severity
1 Vulnerabilities detected
2 Execution or path error

Contributing

We welcome contributions! Please review our Contributing Guide, Code of Conduct, and Security Policy.


License

Distributed under the MIT License. Copyright (c) 2026 Sanjiv - Vigilo.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vigilo-0.3.0.tar.gz (61.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vigilo-0.3.0-py3-none-any.whl (46.0 kB view details)

Uploaded Python 3

File details

Details for the file vigilo-0.3.0.tar.gz.

File metadata

  • Download URL: vigilo-0.3.0.tar.gz
  • Upload date:
  • Size: 61.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for vigilo-0.3.0.tar.gz
Algorithm Hash digest
SHA256 8eb74beacbfce459e583cfbf048909e4b1712591a8257603425a35e51753c7ba
MD5 4b50fc0bd792e3f567c31512613ec992
BLAKE2b-256 d73de23bf82bfecba996bb7de971698715f51c3fe1cd709da28d2ab21f773c3f

See more details on using hashes here.

Provenance

The following attestation bundles were made for vigilo-0.3.0.tar.gz:

Publisher: release.yml on Sanjiv215/VIGILO-Python-Package

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file vigilo-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: vigilo-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 46.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for vigilo-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a7b937047111ca34fe05aeefba22bf027d515d7d500f46754f6042d060ab9047
MD5 4107bf06de385ebc7c119fb9ef01ec09
BLAKE2b-256 5cb9e4efaa03093e7f2feff8155adfef5e78c203b989f2bf31145b75a193bc9c

See more details on using hashes here.

Provenance

The following attestation bundles were made for vigilo-0.3.0-py3-none-any.whl:

Publisher: release.yml on Sanjiv215/VIGILO-Python-Package

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.1

2 files

This release

0.3.0 This release

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page