Is Ironheights free and open source?
What is free
The Community edition is everything that exists today:
- the
ironheightsCLI (scan,fetch,safe-install,advisories,baseline,verify,quarantine,guard,audit-config,review,rules,doctor,bench); - the OpenClaw guard plugin;
- all 35 published rules, documented in the rules reference;
- the advisory OpenClaw skill;
- the free tools on this site, including the browser scanner, the skill safety checklist and the malicious skill tracker.
There is no account, no sign-up, and no usage limit in the CLI.
The license
Ironheights is licensed under Apache-2.0. You can use it commercially, modify it, and redistribute it under the license terms, including in CI pipelines for clients. It is provided without warranty, as the license and our terms state. The full source, issues and releases are in the GitHub repository.
Why open source matters for a security tool
You should not have to trust a security tool's marketing. Because the rules are published, you can read exactly what each one matches, test it against your own skills, and see where it misfires. Our benchmark publishes the method, the per-sample results and the limits, including the fact that our first corpus is small, synthetic and written by us, so it is a regression check rather than a detection rate.
What is planned, and what is not promised
The pricing page lists Pro, Team, a Threat Intel API and Enterprise tiers. Those are plans, and the prices shown are early hypotheses. Features such as a sandbox, a credential broker and a team console are on the roadmap, not in version 0.3.0. We do not sell anything today, and the free CLI does not depend on a paid service.
How to contribute or report a problem
Bug reports, false positives and missed patterns are most useful as GitHub issues with a minimal, harmless example that reproduces them. Please never attach a real malicious skill; describe the technique instead. Security vulnerabilities in Ironheights itself should go through a private GitHub security advisory, as described on the security page. Rule changes are checked against the published rule reference, the synthetic test corpus and the scanner's parity tests before release, so a contribution comes with a test that shows what it matches and what it does not.
Limits
Free does not mean complete. Ironheights is a static, rules-only scanner (the guard plugin only logs by default): it cannot see payloads on linked websites, runtime behavior, or novel techniques its rules do not describe. See what Ironheights does not detect and the limitations page.
Sources
- Ironheights LICENSE (Apache-2.0), GitHub.
- Ironheights README, GitHub.
- Apache License 2.0, Apache Software Foundation.