Plumber - CI/CD security for GitLab and GitHub
Open-source tool that maps CI/CD pipelines, finds security leaks, and scores your setup — for GitLab and GitHub
| What is it | Open-source tool that maps CI/CD pipelines, finds security leaks, and scores your setup — for GitLab and GitHub |
|---|---|
| Pricing | Freemium |
| Free tier | Yes |
| Platform | Web Application |
| Best for | Scanning CI/CD pipelines for security vulnerabilities and misconfigurations, Automating compliance audits for GitLab and GitHub projects |
| Domain registered | 2026 |
Data updated Aug. 1, 2026
What does Plumber - CI/CD security for GitLab and GitHub do?
Plumber is an open-source CI/CD security scanner built specifically for GitLab and GitHub. It doesn't just check your code — it looks at your pipelines themselves. Plumber maps every pipeline across your repositories, then surfaces exposed secrets, misconfigured jobs, and risky actions that attackers love to exploit. The tool then assigns a single letter grade — the Plumber Score — from A (strong) to E (critical issues), making it dead simple to understand and communicate your pipeline security posture to teammates or auditors.
You can start with the CLI, running scans locally or inside your CI as a GitHub Action or GitLab CI component. The open-source CLI is free and scans one pipeline at a time. When you need to monitor your whole organization, the Plumber platform provides a dashboard with drift alerts, compliance reports, and an AI agent that can automatically apply fixes (with a full audit trail). The enterprise plan adds unlimited projects, AI-driven suggestions, and dedicated support. The platform itself is free for up to 10 projects.
This tool is for DevOps engineers who want to catch pipeline misconfigurations before they become breaches, security teams that need to prove compliance continuously, and anyone managing multiple repos on GitLab or GitHub who wants an automated way to stay secure. If you're tired of manual security reviews and want something that plugs straight into your existing workflow, Plumber is worth a look.
Key features
What makes it stand outWho is Plumber - CI/CD security for GitLab and GitHub for?
Who benefits most from this toolPricing
Free tier available — start without a credit cardOpen Source CLI
- 1 pipeline
- advisory fixes
- scan anything from your terminal
Platform Free
- Up to 10 projects
- core CI/CD controls
- 7-day history
- scheduled scans
- community support
Enterprise
- From 10+ projects to unlimited
- AI fixes & suggestions
- unlimited history
- portfolios
- dedicated support
Trust & presence
Gallery
Click any image to enlargeAlternatives in DevOps & CI/CD
Full-stack observability platform that ingests, analyzes, and correlates logs, metrics, and traces in real time
Similar tools
AI DevOps agent for GitHub Actions — monitors workflows, detects failures, suggests fixes, and optimizes CI/CD costs
AI-powered DevSecOps platform that manages the entire software lifecycle from planning to deployment in one place
Git repository management with built-in CI/CD, AI-powered code tools, and deep Jira integration for development teams.
AI-enhanced DevSecOps platform that unifies planning, coding, security, and deployment with AI agents.
Open source tool for supply chain security analysis in CI/CD pipelines — scans for malicious packages.
AI-powered application security platform that scans code, dependencies, and infrastructure for vulnerabilities and provides automated fixes.
AI proxy for enterprises — redacts PII, blocks prompt injections, controls spend across 600+ models
AI-powered code security scanner — connect your GitHub repo, find vulnerabilities, and get actionable fix reports in seconds.