RepoWarden runs a monthly LLM-deep readiness scan across every active repo. Each finding includes the file, the line, the affected dependency version, and a reproduction step — no theoretical noise. Fix the real issues before your assessor does.
Included on the Business plan. No credit card required to view a sample report.
Cyber Essentials Plus is a UK government-backed certification with a specific technical control set — not the loose "best practice" checklists you'll see in most blog posts. The five controls that touch your code directly are:
Most LLM-driven security tools hallucinate. They report SQL injection in code that uses parameterised queries, or flag a CVE in a dep your project doesn't actually use. To an assessor that's worse than no report — it costs trust and time.
RepoWarden's scanner runs under strict rules of engagement: every high/critical finding must include a working reproduction step or get downgraded. Every claim is then mechanically verified — file existence, line number, CVE-vs-version match — before it lands on your kanban. Findings that fail verification are dropped silently. You see the survivors.
/repos/<your-repo>/security — show it to your assessor.Does this replace a CE+ assessor? No — CE+ is an audited certification. RepoWarden gets you to a clean state before the assessor arrives. Far cheaper than a re-audit fee.
Will it create noise tickets? No. We deliberately drop findings the verifier can't ground in real code. The trade-off is a quieter kanban over a busy one.
How often does it run? Once a month at most, per repo. We skip if HEAD hasn't changed.
What about non-CE+ best practice? Findings include a ceFailure flag — those that directly cause a CE+ failure are tagged, the rest are general hygiene improvements.
The Business plan includes monthly CE+ scans on every repo, plus the rest of RepoWarden's automated maintenance — dep PRs, CI fixes, test generation, runtime EoL alerts.
Comparing CE vs CE+? See our breakdown.