Worried about uploading source code to the cloud? Observer is an offline, privacy-first scanner for Go, PHP, Python & JS. It catches security and quality bugs with no account and no upload — your code never leaves the machine. The built-in engine runs instantly; optional Semgrep & PHPStan go deeper, 100% locally. A dashboard shows health + security scores. Free on GitHub; Pro unlocks extra engines.
Maker here. I built Observer because every scanner I tried wanted my code in the
cloud. Observer runs fully offline — no account, no telemetry — and still catches
secrets, SQLi, debug flags, and type errors via built-in rules or your local
PHPStan/Semgrep.
Free & MIT: github.com/sanks205/getobserver
Pro (offline license, background checks): observerly1.gumroad.com
What rule would you want it to add? Feedback very welcome.