Stop shipping vulnerabilities.
Start shipping confidence.

SecHive automatically scans your Maven projects against 318,000+ known vulnerabilities from the National Vulnerability Database. Free, open-source, and zero-configuration.

<!-- Add to your pom.xml -->
<plugin>
  <groupId>io.github.dodogeny</groupId>
  <artifactId>sechive-maven-plugin</artifactId>
  <version>2.2.1</version>
</plugin>

# Then run
mvn clean verify

# That's it. You're protected.
318,000+ CVEs Tracked
3 min Scan Time
100% Free Forever

The Hidden Danger in Your Dependencies

Every dependency is a potential security risk. Most developers discover vulnerabilities weeks or months too late.

🚨 It's 3 AM. Your phone rings.

Your production application is down. A critical security vulnerability in a dependency you didn't even know you were using has been exploited. The breach affects thousands of users. Your team scrambles to patch the issue, but the damage is done.

This nightmare scenario happens more often than you think.

84% of codebases contain at least one known vulnerability
26,000+ new CVEs discovered in 2023 alone
80+ dependencies in average applications (hundreds more transitively)
Weeks before vulnerabilities are discovered without scanning

Security Scanning That Actually Works

SecHive turns security from a quarterly audit into a seamless part of your build process.

❌ Before SecHive

✓ BUILD SUCCESS
Total time: 45 seconds

You have no idea that log4j-core 2.14.1 has 37 known vulnerabilities, including CVE-2021-44228 (Log4Shell) with a CVSS score of 10.0

✅ After SecHive

🔴 CRITICAL VULNERABILITIES DETECTED

📦 Vulnerable Dependency: log4j-core 2.14.1
🔴 CVE-2021-44228 (Log4Shell) - CVSS 10.0
🔴 CVE-2021-45046 - CVSS 9.0
+ 35 more vulnerabilities

💡 Upgrade to log4j-core 2.17.1 (resolves all CVEs)

Now you know. Now you can fix it.

Everything You Need, Nothing You Don't

Built for developers who want security without the complexity.

🚀

Zero Configuration

Add one plugin to your pom.xml. That's it. No complex YAML files, no security expertise needed, no learning curve.

🧠

Intelligent Auto-Updates

Automatically downloads the latest NVD database on first run, then intelligently updates only new/changed data. Always scanning against fresh vulnerability data.

📊

Beautiful Reports

HTML reports with visual dependency trees, direct NVD links, severity breakdowns, and trend analysis showing new vs. resolved vulnerabilities.

📈

Historical Tracking

Track your security posture over time. See exactly which CVEs were resolved, introduced, or remain pending between scans.

CI/CD Ready

Works seamlessly with GitHub Actions, Jenkins, GitLab CI, Azure DevOps, CircleCI, and any platform that runs Maven.

🐳

Docker Mode (Pro)

Run as a standalone Docker container with continuous Git polling or local project scanning. Supports any Git repository: GitHub, GitLab, Bitbucket, Azure DevOps, self-hosted Git servers. NEW: Scan local projects on disk with watch mode for continuous monitoring.

💾

Smart Caching

First scan: 20-30 minutes (one-time database download). Every scan after: 2-3 minutes. Intelligent caching reduces scan times dramatically.

Real Results from Real Projects

How SecHive transformed security for a legacy enterprise application

150-module Maven monolith, 8 years old, 800+ dependencies

147 Vulnerabilities found on first scan
98 Critical/High CVEs fixed in first month
3 min Scan time (vs 2 weeks manual audit)
Same Day Time to patch critical issues

"Security went from a quarterly audit to a continuous, automated check on every build. Game changer."

Get Started in 5 Minutes

Three simple steps to secure your Maven project

1 Add the Plugin

<!-- Add to your pom.xml --> <plugin> <groupId>io.github.dodogeny</groupId> <artifactId>sechive-maven-plugin</artifactId> <version>2.2.1</version> </plugin>

2 Run Your Build

$ mvn clean verify

3 Review Your Report

Open target/sechive-reports/sechive-report.html in your browser.

That's it! You're now scanning for vulnerabilities.

View Full Documentation

When Community Isn't Enough

Commercial Edition pays for itself in hours, not months. Here's how teams justify the upgrade.

💰 The Commercial Edition ROI Story

Without Commercial Edition

  • 🐌 Scans take 2-3 minutes
  • 100 builds/week = 3-5 hours scanning time
  • ❓ "Which dependency should I upgrade?" - 2 hours research
  • 📋 Manual license audits - 8 hours/quarter
  • 🔍 Limited to 10 historical scans - no trend analysis
  • 📧 Manual email alerts - slow response
  • 🔎 Tracing transitive dependencies - 30-45 min per issue

With Commercial Edition

  • ⚡ Scans take 15-20 seconds (15x incremental, 6x microservices)
  • 💨 Same 100 builds = 25-30 minutes (save 2.5-4.5 hours weekly)
  • 📊 Real-time resource monitoring - beautiful dashboards show CPU, memory, threads + trend analysis (NEW!)
  • 🔮 AI-powered updates: "Upgrade to 2.16.1 - resolves 12 CVEs, safe"
  • ⚖️ Automated license compliance - 0 hours (prevents $50K+ violations)
  • 📊 PostgreSQL/MySQL unlimited history - query years of data
  • 🚨 Real-time Slack/Teams/Discord alerts - seconds, not days
  • 🌳 Interactive dependency tree - 5 seconds to find any CVE source
$149/month = $1.50 per developer per day
Save 2.5-4.5 hours weekly + prevent one $50K breach = 300x ROI
Less than a cup of coffee. More valuable than 10 hours of manual security work.

You Need Commercial Edition If...

👥 You Have a Team (3+ developers)

Time is money. If 5 developers save 10 minutes each per day with faster scans, that's 20+ hours saved per month. Your team's time costs more than $149.

🏢 You're Building Commercial Software

License compliance isn't optional. One GPL violation can cost $50,000+ in legal fees. Commercial Edition automatically checks 150+ license combinations and prevents compliance disasters.

🚨 You Need Compliance Audits

SOC 2, ISO 27001, PCI-DSS all require vulnerability tracking and SBOM documentation. Commercial Edition provides unlimited scan history, PDF reports, and CycloneDX/SPDX SBOMs that auditors actually accept.

🤔 You Waste Time on "Which Version Should I Upgrade To?"

Predictive update analysis is a game-changer. Instead of spending 2 hours researching which spring-security version to upgrade to, Commercial Edition tells you: "Upgrade to 6.2.1 - resolves 8 CVEs, introduces 0 new ones, safe update."

📊 You Want to Optimize Performance (NEW in v2.0.0!)

See exactly how your builds use resources with beautiful real-time dashboards showing CPU, memory, threads, and GC activity. Get AI-powered recommendations for JVM tuning and thread pool optimization. Identify bottlenecks instantly with color-coded sparkline graphs and intelligent alerting. NEW: Historical trend analysis automatically detects regressions by comparing each build to the last 10 builds, with actionable insights like "⚠ Memory usage increased by 15% - consider increasing heap size".

📊 You Want Real Observability

Security isn't just about scans - it's about trends. Commercial Edition provides unlimited historical tracking, PostgreSQL/MySQL storage for querying years of scan data. See your security posture improve over time, not just "scan passed/failed".

🔔 Your Team Misses Critical Alerts

Webhook notifications to Slack, Teams, or Discord mean your security team knows about CRITICAL vulnerabilities within seconds, not days. Real-time alerts = faster response = reduced risk exposure.

🚀 You Use GitHub Actions or Azure DevOps

Native integration with GitHub Code Scanning & Azure Pipelines. SARIF reports automatically appear in GitHub Security tab. PR comments with vulnerability summaries. Progressive policy enforcement - fail only on NEW vulnerabilities, not existing ones.

🌳 You Struggle with "Where Is This Vulnerability Coming From?"

Interactive D3.js dependency trees show exactly which transitive dependency introduced that critical CVE. Version conflict detection ("Jar Hell") catches when multiple versions of the same library exist. See vulnerability propagation paths at a glance.

What You Get With Commercial Edition

🐝

Bee Swarm Optimization

Intelligent task distribution with work-stealing queues, priority-based selection. 20-30% base performance + 40-60% additional throughput.

💾

Persistent Scan Cache

Cross-project caching with 80-95% hit rates. 15x faster incremental builds, 6x for microservices, 1.6x for monorepos.

🛡️

Threat Intelligence

Real-time enrichment from NVD, MITRE ATT&CK, CISA KEV, Recorded Future, ThreatConnect. Enhanced risk scoring.

🔮

Predictive Updates

AI-powered Maven Central analysis: "Upgrade to 2.16.1 - resolves 12 CVEs, introduces 0 new ones, safe update."

⚖️

License Compliance

150+ license checks, GPL/AGPL violation prevention, 3 built-in policies (Enterprise, Permissive, Strict).

📊

Advanced Reports

PDF, SARIF (GitHub Code Scanning), Excel. CycloneDX & SPDX SBOM with VEX support.

🗄️

Unlimited History

TimescaleDB/PostgreSQL/MySQL/H2 persistent storage. CVE trend tracking, time-to-remediation metrics, automatic schema migrations.

🔔

Real-Time Alerts

Email & webhooks to Slack, Microsoft Teams, Discord. WebSocket monitoring for instant critical CVE alerts.

🔗

SIEM Integration

Export to Splunk, Elasticsearch, IBM QRadar, ArcSight, LogRhythm. Centralized security monitoring.

🚀

CI/CD Integration

Native GitHub Actions & Azure DevOps integration. Jenkins, CircleCI, GitLab CI support with SARIF reports.

🐳

Docker Mode

Standalone container with Git polling or local project scanning. Supports GitHub, GitLab, Bitbucket, Azure DevOps, self-hosted servers. NEW: Watch mode for continuous local monitoring.

🌳

Dependency Insights

D3.js interactive dependency trees, version conflict detection ("Jar Hell"), vulnerability propagation paths.

🔍

Premium Scanners

Grype scanner integration, multi-scanner parallel processing, enhanced OWASP configuration.

⚠️ The Cost of NOT Upgrading

$50,000+
Average cost of one security breach (IBM Security)
$30,000+
Legal fees for license violations (GPL in commercial code)

One prevented security incident or license violation pays for 20+ years of Commercial Edition.
$149/month is insurance, not an expense.

✅ Zero-Downtime Subscription Model

Your builds never fail. If your monthly subscription expires, SecHive automatically falls back to Community Edition - no interruptions, no broken builds.

⏰ Your SecHive Commercial Edition license has expired!
🔄 Please renew your monthly subscription to continue using commercial features
💳 Visit https://sechive.lemonsqueezy.com/billing to renew your subscription
🆓 Falling back to Open Source Edition for this scan

📋 Community Edition features still available:
✓ Basic Vulnerability Scanning
✓ HTML, JSON, CSV Reports
✓ In-Memory Database Support
✓ OWASP Dependency-Check Scanner
✓ Multi-module Scanning

Scans continue with community features. Renew anytime to restore commercial features instantly.

See It In Action: Real-World Scenarios

Scenario 1: Microservices Team (15 services, 200+ builds/day)

Without Commercial:
  • 200 builds × 2 min = 6.7 hours scanning daily
  • No shared cache = duplicate work
  • Manual Slack notifications
  • No GitHub Security integration
With Commercial:
  • 200 builds × 20 sec = 1.1 hours daily (83% faster)
  • Persistent cache across services (6x speedup)
  • Real-time Slack alerts for critical CVEs
  • SARIF reports in GitHub Security tab
Save 28 hours/week = $4,200/month in developer time

Scenario 2: Enterprise Compliance (SOC 2, ISO 27001)

Requirement: Quarterly security audits, SBOM documentation, license compliance

Community Edition: Manual audits (16 hours), no SBOM, no license tracking = $8,000/quarter

Commercial Edition: Automated CycloneDX/SPDX SBOMs, PostgreSQL historical tracking, license policy enforcement, PDF audit reports = $0 manual work

Save $32,000/year in compliance costs alone
Plus instant audit-readiness, not quarterly scrambles

Scenario 3: Dependency Hell Mystery

Problem: "Which transitive dependency is bringing in log4j 2.14.1 with 37 CVEs?"

Community Edition: Run mvn dependency:tree, manually grep for log4j, trace back = 30-45 minutes

Commercial Edition: Open interactive D3.js dependency tree, click on log4j, see full path highlighted = 5 seconds

"I used to spend 2-3 hours per week tracing dependency chains. Now I just click the tree." - Senior DevOps Engineer

Try Commercial Edition Risk-Free for 14 Days

Monthly subscription with automatic renewal. Cancel anytime. See the difference yourself.

Start Free Trial →

14-day free trial • Cancel anytime before billing • See the difference in your first week

Choose Your Edition

Community Edition is free forever. Upgrade to Commercial Edition for advanced features.

Community Edition

Free forever

Perfect for individual developers and small teams

  • ✅ Basic Vulnerability Scanning (318K+ CVEs)
  • ✅ HTML, JSON, CSV Reports
  • ✅ In-Memory Database
  • ✅ OWASP Dependency-Check Scanner
  • ✅ Multi-module Support
  • ✅ 10 Historical Scans per Project
  • ✅ CI/CD Integration
  • ✅ Community Support
Get Started

Ready to Secure Your Maven Projects?

Join developers who are shipping secure software with confidence.