Deterministic codebase intelligence

Understand the system.Change it with confidence.

CodeTrawl turns structure, history, security and change impact into traceable evidence before your next decision.

Sweeping your own repo takes a free account — we'll keep the URL and run it the moment you land. Or read one already swept, no account at all.

CODETRAWL / PALLETS-FLASKANALYSIS READY
CodeTrawl repository overview for pallets/flask
7languages parsed
34computed signals
File → linetraceable evidence
No AIrequired for the read

GUIDED PRODUCT TOUR

One repository. Four decisions.

Stay in context as CodeTrawl moves from orientation to change impact, security and supply-chain health.

01 / Orient

Know where to start.

Turn a repository into a shared map of health, history and the findings that deserve attention first.

  • Computed top finding
  • Health across every analysis lens
CodeTrawl repository overview for pallets/flask

02 / Change

See what the edit can touch.

Follow callers, dependents, complexity and untested paths before a local change becomes a system-wide surprise.

  • Function-level blast radius
  • Evidence attached to the source
CodeTrawl source and blast-radius analysis

03 / Review

Inspect the exact risk.

Security findings name the pattern, location and evidence. Your team reviews the same facts the product used.

  • Named deterministic rules
  • File and line-level evidence
CodeTrawl deterministic security review

04 / Maintain

Keep dependency drift visible.

Find vulnerable, outdated and deprecated packages across npm, PyPI and Cargo without losing registry context.

  • CVE-aware package health
  • npm · PyPI · Cargo
CodeTrawl dependency health analysis

HOW THE READ IS BUILT

How CodeTrawl builds the read.

Narration is optional. The analysis remains useful with every AI feature switched off.

01

Parse

AST structure across seven languages

02

Connect

Calls, imports, history and ownership

03

Test

34 deterministic repository signals

04

Prove

Evidence at file, function, line or package

TRUST MODEL

The evidence layer stands on its own.

AI can explain a result. It cannot create one, strengthen one or decide what is true.

Read the security model
01

Rules before prose

Repository facts are computed before anything is explained.

02

Evidence stays attached

Every material finding points back to a file, function, line or package.

03

AI never decides truth

Narration can clarify a result. It cannot create or upgrade one.

OPEN REPORTS

Don't watch a demo. Open the product.

Real repositories and computed findings. No account required.

Questions worth asking first.

Where does my code go?
We take two temporary copies to analyze it — a metadata-only git clone for history, and the repository archive, because the parsers have to read the files — and the analysis process deletes both when it is done. What we keep afterwards is the result: paths, structure, symbol names, metrics, findings. Not your files, with a short list of named exceptions we spell out rather than round off. The whole answer is on one page, including the parts that are inconvenient for us.
Is this just an LLM guessing about my repo?
No — the analysis engine calls no AI at all. The clone, the parse, the call graph and every signal are computed by code, and with no API key configured the product loses its narration and nothing else. The AI layer sits on top in three clearly different shapes: the health verdict is written from the computed signals alone, the briefing also draws on what the model knows about well-known projects, and the per-function explainer reads that one function’s source when you click it. We split those out instead of claiming the strongest one covers all three.
What does it cost?
Every panel is free on one repo, private repositories included — the source browser, the call graph, Faultline, the AI briefing, the grade. Nothing is held back to make the free tier feel thin. What you pay for is keeping more than one repo on the go, a grade on every pull request, and a daily re-sweep that tells you when something regressed. Plans and limits.
What happens if CodeTrawl disappears?
The source is public and licensed under PolyForm Noncommercial, so you can read exactly what it does to your code and run it yourself — the MCP server is one npx command and does its analysis on your machine, with no CodeTrawl server in the path at all. We are one person, not a funded team, and we say so plainly; that is the reason the escape hatch exists rather than something to discover later.

START WITH THE CODE

Know what your next change can touch.

Analyze one repository free. Private repositories included.

Sweeping your own repo takes a free account — we'll keep the URL and run it the moment you land. Or read one already swept, no account at all.

Traceable evidenceNo installationAI optional