See your cloud.
Secure what matters.

Plexavo helps modern teams find dangerous cloud misconfigurations, understand their real impact, and turn security findings into actions.

$ uv tool install plexavo
OPEN SOURCEBUILT FOR MODERN INFRABUILD IN PUBLIC
32
checks against real AWS data
6
categories: IAM, network, storage, encryption, logging, usage
0
bytes of your account sent anywhere
100%
of detection logic readable on GitHub
DISCOVER
UNDERSTAND
PRIORITIZE
FIX
VERIFY

Cloud gets complicated.
Security shouldn't.

Modern infrastructure moves fast. One forgotten permission, exposed resource, or weak identity control can quietly become the easiest way into your environment.

Plexavo is designed to give developers and small teams a clear security layer around their cloud, without burying them in endless alerts.

01 / VISIBILITY

Know what's exposed

Resources, paths, boundaries.

02 / RISK

Prioritize risk

9.8CRITICAL
03 / ACTION

Fix with context

FINDFIXVERIFY

6 Catagories
32 Checks.Zero Fluff.

Run against real accounts, not a best-practices PDF. Each finding is something specifically true about your setup.

IAM

Privilege-escalation paths, wildcard admin, cross-account trust, root usage, dormant credentials.

privesc chaining most scanners skip

Network

Security groups and RDS instances exposed to 0.0.0.0/0 when they shouldn't be.

protocol- and port-aware wording

Storage

Public S3 buckets via ACLs, bucket policies or missing Block Public Access; buckets with no access logging.

three separate public-exposure paths

Encryption

Unencrypted EBS volumes, RDS instances and S3 buckets, including the ones auto-created for you.

at-rest coverage across three services

Logging

CloudTrail coverage and encryption, GuardDuty status, so a break-in would not go unseen.

catches GuardDuty gaps other tools miss

Usage

Permissions granted but never used, roles nobody has assumed in 90+ days. Risk sitting around for nothing.

granted actions vs. real CloudTrail usage

From cloud sprawl
to clear action.

Security should fit into the way your team already ships software.

01

Connect

Point Plexavo at the infrastructure you want to inspect.

02

Scan

Run security checks across your cloud configuration.

03

Understand

See the issue, impact, affected resource, and context.

04

Fix

Remediate, verify, and keep moving.

Same account,
same session.
Prowler and PMapper too.

Not a paper comparison. A real, same-account run. Here's where Plexavo is genuinely different, stated honestly.

Plexavo

open-source · plain-English · 32 checks
  • Impact / attacker move / exact fix on every finding
  • General-purpose unused-permission analysis across any service
  • Reliable GuardDuty detection
  • One clean install, no version-compat surprises

Prowler

mature · 400+ checks · compliance mapping
  • Far wider service and check coverage
  • Native CIS / SOC2 / PCI / HIPAA mapping
  • Findings are one terse technical line
  • No "what would an attacker do" framing

PMapper

specialist · IAM graph simulation
  • True graph-based privilege-escalation modelling
  • No severity rating at all
  • No remediation guidance
  • Rawest output of the three

Plexavo is an early single-developer project measured against years-mature tools. The full write-up, including its own gaps, is in the repo's docs/COMPARISON.md.

Not another
security dashboard.

Plexavo is being built around a simple idea: security findings are only useful when they change what someone does next.

01Signal over noise
Less alert fatigue. More useful findings.
02Developer-native
Security that fits modern engineering workflows.
03Community-powered
Open tooling, feedback, research, and contributions.

Security gets stronger
when everyone can inspect it.

Plexavo is being built in the open. Test it. Break it. Open an issue. Suggest a check. Contribute a fix. The best security tooling should have a community behind it.

github.com/plexavo/Plexavo★ BUILD IN THE OPEN

Built for the teams
moving fast.

Your infrastructure can be sophisticated without your security process becoming a full-time job.

01Cloud-first

Focused on the security problems modern cloud teams actually face.

02Open by design

Community feedback is part of the product, not an afterthought.

03Actionable

Findings should lead naturally from discovery to remediation.

Field notes on AWS security.

Concrete write-ups on the misconfigurations Plexavo looks for and what they cost when they are missed.

Does your AWS setup need S3 server access logging?

How to check whether it is enabled, decide if you actually need it, and the CloudTrail data events angle most guides leave out.

Read
All posts

Make your cloud
harder to break.

Explore the project, run it in a safe environment, and tell us what you find.

Explore Plexavo on GitHub ↗