ArchSetu
ArchSetu

One clone. Every signal. Under 60 seconds.

Everything a senior engineer would check on a codebase, computed - not guessed

No AI reads your code and summarizes it. ArchSetu parses the real syntax tree and traces the real call graph, so the same repo produces the same report every time.

Health Score

One number, fully explainable - every point traced back to a specific rule and a specific line.

Call Graph

Every function, every caller, reconstructed from the real syntax tree - not an LLM guess at structure.

Dead Code

Functions with zero known callers anywhere in the codebase, including across languages and frameworks.

Blast Radius

Pick any file: see exactly what breaks, direct and transitive, before you touch it.

Git History & Bus Factor

Ownership concentration and churn computed from real commit history, not a snapshot in time.

Security Risk

Hardcoded secrets, unsafe dynamic execution, SQL injection risk, insecure transport, weak cryptography - the exact file and line, visible only to you.

Dependency Hygiene

Packages imported in source but never declared - the ones one version bump from breaking your build.

Architecture Rules

Layering and boundary violations enforced against rules you define, not a generic linter default.

Security findings are never public. Anyone can see a risk count on a repo's report page, but the exact file and line - the part that actually matters for exploitation - is only ever shown to that repo's verified owner, or to you specifically for a private repo you submitted. Nobody else, ever.

Analyze a Repository

Public or private. Results in under 60 seconds, free of charge.

$

Currently supports GitHub repositories only. Need GitLab or Bitbucket? Email coder@archsetu.com.

Try a popular repo

Your code is never stored. The clone is deleted immediately after analysis.