Inline feedback on GitHub when a PR opens. Catch security flaws before they merge, with weighted scoring by repo and contributor.
“handleBuyer” is executed before the signature check, allowing an unauthenticated caller to trigger buyer state changes.
From sign-in to a scored pull request, in under a minute.
One click with GitHub OAuth. No password, no setup form.
Inline comments with severity, a security flag and a suggested fix.
One score out of 100 per pull request, repository and contributor.
Prepaid credits from $20 a month. Reviews pause at $0.
DiffNova reviews your pull request, comments where the risk is, and rolls findings into a security-weighted score.
Every pull request is reviewed for security and quality issues, with findings ranked by severity.
Comments land on the PR as inline notes plus a summary — right where your team already reviews.
Findings roll up into one score per repository and per contributor, weighted by real risk.
Sign in with GitHub OAuth. Your org is ready in one click.
Connect the DiffNova GitHub App and choose which repositories to review.
Open a pull request — DiffNova posts inline findings and a summary comment.
Security-weighted scores per repo and contributor show where risk concentrates.
Findings are weighted by severity — a critical auth bypass moves the score far more than a style nit. Scores roll up per repository and per contributor.
Prepaid LLM credits each month. Unused credits carry over. Or bring your own OpenAI / Claude key for $5/mo.
Activate security-weighted scoring and AI reviews with prepaid credits that stop at zero.