Skip to content
Tracked since2025
0 reviews tracked·1 press mentions

The Bottom Line

Entry price

Free plan available, paid tiers above

Biggest pro

Secrets detection

Biggest con

Learning curve

TL;DR - TruffleHog

  • TruffleHog is an open-source tool for finding secrets in code
  • It detects credentials, API keys, and tokens in repositories
  • Free and open-source, Enterprise version available
Pricing: Free plan available
Best for: Growing teams

What is TruffleHog?

Editorial review
TruffleHog finds secrets in code and commits. Credential scanning that checks history-security that catches leaked secrets. The scanning is thorough. The history checking matters. The findings prevent incidents. Security teams use TruffleHog for comprehensive secret detection.

Available on: Web

Pros & Cons

Pros

  • Secrets detection
  • Open source
  • Good accuracy
  • Active development
  • CI/CD integration

Cons

  • Learning curve
  • False positives
  • CLI focused
  • Enterprise features paid
  • Configuration needed

Key Features

Secret detectionGit scanningVerified secretsCI/CD integrationOpen sourceMultiple sources

Pricing Plans

Most Popular

Open Source

Free

Free

  • Secret scanning
  • 700+ detectors
  • Git history

Enterprise

Free

Custom

  • Dashboard
  • RBAC
  • Support

Reviews

Be the first to review TruffleHog

Your take helps the next buyer. Verified LinkedIn reviewers get a badge.

Write a review

Best TruffleHog Alternatives

Top alternatives based on features, pricing, and user needs.

Most buyers shortlist 2 or 3 tools before committing. Pull a side-by-side comparison or browse the full alternatives shortlist below.

Explore More

TruffleHog FAQ

Is TruffleHog free?

Open source version free. Enterprise from sales. Secret scanning.

What is TruffleHog?

Find secrets in code. Scans git repos, S3, etc. Security tool.

TruffleHog vs GitGuardian?

TruffleHog open source. GitGuardian managed service. TruffleHog for DIY.

Guides & Articles