- Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…
- Scans now check for exposed credentials in source code, including unused code and tests, and distinguish suspected exposures from placeholders. This check runs offline, without trying discovered…
- Use --model and --effort when generating patches, validating findings, verifying fixes, or matching and comparing saved scans. Deep Scan workers and patches generated during a scan also respect…
- Patch, validation, and fix-verification commands now respect custom model providers and their authentication settings. Amazon Bedrock users get clearer authentication errors and cost estimates for…
- Scans include previously overlooked C++ headers (.hh and .hxx), server-rendered templates (EJS, ERB, and PHTML), and Vyper source files when selecting code to review. (#1079, #1197,
- On Unix, scans check that the sandbox works before starting paid model calls. Completed results are kept if you cancel follow-up work. CSV exports can now be reimported without rejecting multiple…
Codex Security by OpenAI
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Recently added on Oct 10, 2026. The description, category and pricing were filled in from public metadata and have not been checked by an editor yet.
What Codex Security does
Key facts
| Maker | OpenAI |
|---|---|
| First released | July 2026 |
| License | Apache-2.0 |
| Main language | TypeScript |
| Open issues and PRs | 214 |
Pricing
Open source under the Apache-2.0 licence; check the website for any paid hosted plans.
, checked Oct 10, 2026. Prices change often; confirm before you buy.
Quick answers
- Free to start?Yes
- Open source?Yes (Apache-2.0)
- Closest alternativePentAGI · all alternatives
Codex Security alternatives
Best Codex Security alternatives compared · All AI security agents
| # | Agent | Gid Score | Downloads 7d | 7d | 30d | VS Code installs | Stars | Latest release | Price | ||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 196 |
PentAGIVXControl |
31 | — | — | — | — | 25.4K+29/day | 2.2.05d ago | Free (OSS) | ||
| 226 |
StrixStrix |
25 | 9,808 | up 11.5% | down 49.7% | — | 67.6K+209/day | 1.7.05d ago | Free + $29/mo | ||
| 266 |
NodeZeroHorizon3.ai |
18 | — | — | — | — | — | — | Custom | ||
| 293 |
XBOWXBOW |
11 | — | — | — | — | — | — | Usage-based | ||
| 294 |
CAI (Cybersecurity AI)Alias Robotics |
10 | 536 | down 10.4% | down 46.4% | — | 9,846+2/day | — | Free | ||
| 307 |
Dropzone AIDropzone AI |
0 | — | — | — | — | — | — | Custom | ||
| No agents match that filter. | |||||||||||
Head to head: Codex Security vs PentAGI · Codex Security vs Strix · Codex Security vs NodeZero · Codex Security vs XBOW
Ratings from people who use Codex Security
No ratings yet. Used Codex Security? Rate it and say what it is good and bad at.
Codex Security news
-
74 agents added to AgentGid
Symphony, OpenShell, Codex Security, NemoClaw, Agent Browser, Opensre, Caveman, Brag, Open Code Review, Understand-Anything, Codegraph, BrowserSkill and 62 more
-
Codex Security 0.2.0 released
Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…; Scans now check for exposed credentials in source code, including…
What changed: recent Codex Security releases
30 stable releases in the last 90 days · Full changelog
- bump the third-party group across 2 directories with 2 updates
- bump ruff from 0.16.6 to 0.16.7 in /plugins/codex-security
- bump the codex group across 3 directories with 2 updates
- build the native runtime without the SDK
- set up Python for Windows package verification
- report full-output scan failures as errors
- stream large saved scan JSON output
- prefer complete saved rollout copies
- support custom patch validation prompts
- bump @opencode-ai/sdk from 1.18.29 to 1.18.30 in /plugins/codex-security/skills/triage-finding/evals in the third-party group across 1 directory
- bump @linear/sdk from 93.0.1 to 94.0.0 in /sdk/typescript
- seal drafts with empty artifact lists
- use versioned conventional commit titles
- share scan settings across the CLI and SDK
- keep parameterized JUnit names unique
- accept large saved post-scan prompts
- make cost display optional
- collect Desktop and worker session logs
- Classify finding severity with custom rubrics and supporting context through
- Match repeated findings across scan history, preserving confirmed identities
- Open draft GitLab merge requests for verified patches with the existing
- Report component scan progress in headless runs and exclude replayed usage
- Preserve analytics settings in finding workflows and allow 120 seconds for
- Require an explicit request before invoking the security fix verification
- Preserve confirmed finding identities across scans and comparisons, and show
- Improve deduplication with separate screening and pair reviews, validated
- Generate synthetic Standard scan results with scan --mock or the SDK's
- Increase a running scan's total budget from the interactive dashboard when
- Recognize existing Codex authentication in CLI and SDK login status. SDK
- Configure the findings service's full embeddings endpoint with
Codex Security popularity and usage data
The GitHub repository has 11K stars, 484 of them added in the last 30 days. The latest stable release is 0.2.0, published Oct 6, 2026; there were 4 stable releases in the past 30 days. It was mentioned in 204 Hacker News posts and comments over the last 30 days.
Download the raw daily series: codex-security.csv
Gid Score breakdown
Each component is scored 0 to 100 from public signals; a dash means no data for it. Methodology.
Codex Security FAQ
How much does Codex Security cost?
Open source under the Apache-2.0 licence; check the website for any paid hosted plans.
Is Codex Security open source?
Yes. Codex Security is open source, released under the Apache-2.0 license.
How popular is Codex Security?
The GitHub repository has 11K stars, 484 of them added in the last 30 days. The latest stable release is 0.2.0, published Oct 6, 2026; there were 4 stable releases in the past 30 days. It was mentioned in 204 Hacker News posts and comments over the last 30 days.
What is the latest version of Codex Security?
The latest stable release we track is 0.2.0, published on Oct 6, 2026.
What are the alternatives to Codex Security?
The closest alternatives in the same category by Gid Score are PentAGI, Strix, NodeZero, XBOW.
For the makers of Codex Security badges, corrections
Add a live badge to your README or site:
[](https://agentgid.com/agents/codex-security/)
[](https://agentgid.com/agents/codex-security/)
Something wrong or outdated on this page? Send a correction with a link to the official source. More for makers.
Where these numbers come from
GitHub: openai/codex-security. Site rank: openai.com on the Tranco list. See data sources for how each one is collected.
Product facts and pricing were checked against: developers.openai.com, github.com.
