What is a code scan?
In a code scan you upload your source code as a ZIP file. ZeroFlaw extracts it and runs multiple security scanners over the code. You get a detailed list of all vulnerabilities found – from critical security flaws to minor improvement suggestions.
How to start a code scan
- In the dashboard click "New scan".
- Select the "Upload code" tab.
- Drag your ZIP file into the upload area or click to choose a file.
- Click "Start scan".
Which files are checked?
ZeroFlaw detects the programming language automatically and selects the right scanners. Supported languages include:
- JavaScript / TypeScript (including Node.js, React, Vue, Angular)
- Python
- PHP
- Java / Kotlin
- Go
- Ruby
- C / C++
- C# / .NET
- and more – see Scanner engines
File size and limits
| Property | Limit |
|---|---|
| Maximum file size | 200 MB |
| Allowed formats | ZIP |
| Concurrent scans | max. 3 |
node_modules, vendor or .git from your ZIP file. This makes the upload faster and avoids unnecessary findings in third-party code.
What happens behind the scenes?
- Your ZIP file is stored encrypted on the server.
- A worker extracts the file in an isolated environment.
- Multiple scanner engines analyze the code simultaneously (see Engines).
- Results are merged, rated and displayed in your dashboard.
- Your source code is automatically deleted after the scan.
FAQ
My upload fails – what should I do?
Check that your file is a valid ZIP and not larger than 200 MB. Make sure the file is not password-protected.
Can I upload individual files instead of a ZIP?
No, currently only the ZIP format is supported. Simply zip your project – most operating systems can do this with a right-click.
How long does a scan take?
It depends on the size of your project. Small projects often take just 1–2 minutes, larger ones up to 10 minutes. You can see the progress live in the dashboard.