1
0 Comments

AWS Security Tool that explains findings in plain English free, open source, runs on your own machine.

Plexavo scans your AWS account for security misconfigurations public S3 buckets, IAM privilege escalation paths, missing encryption, logging gaps and tells you what's wrong without assuming you already have a security background.

Why I built it: I'm learning cybersecurity right now, and when I set up my own AWS account, I found real misconfigurations I had no idea existed. The tools that already do this well are built by and for security professionals the output assumes you know the terminology going in. If you're a solo founder or small team who set up your own infra because there was nobody else to do it, that output is basically noise.

Plexavo runs locally using your own AWS credentials nothing ever gets sent to me or anyone else. The free scan gives you the raw technical findings. If you bring your own Anthropic API key, it'll also rewrite each finding into plain language: what's actually wrong, what someone could do with it, and the exact command to fix it.

Open source under AGPL-3.0. This is genuinely early first public release, one star so far, still figuring out if this solves a problem other people actually have or just one I personally ran into. If you've deployed your own AWS infra and never had it properly checked, I'd genuinely appreciate you trying it and telling me straight if the explanations make sense or if they're still too technical.

posted toAvatar for product Plexavo
Plexavo