GitHub Secret Scanning

No phone app

  • Recognised40% of the score5
  • Phone app26% of the score0
  • Documented20% of the score84
  • Free plan14% of the score30
Free plan
No
Paid plans from
$19/mo
Runs on
api, self-hosted, Web

Summary

GitHub Secret Scanning is ranked #17 of 22 in dependency management software on Samsung Mobile US Press. It runs on API, Self-hosted, Web. Paid plans start at $19/mo.

GitHub Secret Scanning plans and pricing

All plans
GitHub Secret Protection $19/mo per active committer/month Secret scanning and push protection included for Team and Enterprise · Free for public repositories · Validity checks, Copilot secret scanning, generic patterns, bypass controls, security overview insights, and scan history API included for Team and Enterprise github.com · 4 Oct 2026

Compared on dependency management software

Free plan
Yesgithub.com
Paid from
$19/mogithub.com
Self-hosted deployment
Yesgithub.com

Facts

Purpose
Secret scanning automatically detects exposed credentials so they can be secured before they are exploited.docs.github.com · 4 Oct 2026
Scan coverage
It scans all branches across Git history and also scans issue and pull request content, discussions, wikis, and secret gists.docs.github.com · 4 Oct 2026
Alerts
When it detects a credential leak, GitHub creates an alert on the repository’s Security and quality tab with details about the exposed credential.docs.github.com · 4 Oct 2026
Push protection
Push protection proactively blocks secrets before they reach code.github.com · 4 Oct 2026
Custom patterns
Organizations can define regular expressions to detect organization-specific secrets not covered by default patterns.docs.github.com · 4 Oct 2026
Generic patterns
Generic patterns can detect secrets not tied to a specific provider, including private keys, connection strings, and generic API keys.docs.github.com · 4 Oct 2026
AI detection
AI-detected secrets can identify unstructured secrets such as passwords.docs.github.com · 4 Oct 2026
Provider integration
GitHub partners with service providers to validate detected secrets and may notify a provider so it can take action, such as revoking the credential.docs.github.com · 4 Oct 2026
Validity checks
Validity checks determine whether a detected secret is still active and may contact its issuing service to check whether it was revoked.docs.github.com · 4 Oct 2026
Public repositories
Secret scanning runs automatically for free on public repositories.docs.github.com · 4 Oct 2026
Private repository access
Organization-owned private and internal repositories can use secret scanning with GitHub Secret Protection enabled on GitHub Team or GitHub Enterprise Cloud.docs.github.com · 4 Oct 2026
Enterprise option
GitHub Enterprise Server supports secret scanning for user-owned repositories when the enterprise has GitHub Secret Protection enabled.docs.github.com · 4 Oct 2026
Public monitoring
An enterprise can enable public monitoring to detect secrets its members leak in public repositories across GitHub.docs.github.com · 4 Oct 2026

Company

Founded
2008github.com · 28 Sept 2026
Headquarters
San Francisco, California, United Statesgithub.com · 28 Sept 2026

Best GitHub Secret Scanning alternatives

See all 12

Where it ranks on Samsung Mobile US Press

Is GitHub Secret Scanning yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources