Skip to content
Reshift

Reshift

DEPRECATED
Category: SAST
License: Proprietary (plugins open source)
Suphi Cankurt
Suphi Cankurt
+8 Years in AppSec
Updated February 7, 2026
2 min read
Key Takeaways
  • Reshift is no longer available at its former product domain
  • The platform supported Java and added JavaScript scanning in February 2021
  • Historical materials describe a Datalog engine, machine-learning triage, and remediation guidance
  • The last public npm package was published in 2021; the main public plugin repository last changed in 2022
  • The former product domain should not be used to access Reshift

Reshift was a developer-focused SAST platform for Java and JavaScript. The service is no longer available at its former product domain, so this page is retained as a historical reference.

Warning
Former domain no longer belongs to the product

What Reshift was

A February 2021 company announcement described Reshift as a SaaS application security platform. It added JavaScript scanning to an existing Java capability.

The announcement said Reshift used a Datalog scanning engine, vulnerability-detection rules, and machine-learning-assisted triage. These are historical vendor claims, not current product capabilities or independently benchmarked outcomes.

Reshift’s public npm plugin described curated JavaScript security checks, issue explanations, remediation snippets, and developer guidance. The plugin required a Reshift account and token to run a scan.

The separate IntelliJ plugin targeted Java developers. Its repository describes security findings, remediation snippets, and supporting documentation inside the IDE.

Why Reshift is marked deprecated

The former Reshift domain no longer serves the product and now redirects to an unrelated site. No current official Reshift product page, successor, acquisition, or rebrand was identified during this audit.

Public artifacts are also old:

ArtifactLast verified activity
npm package @reshiftsecurity/reshift-plugin-npmVersion 2.0.2 published August 6, 2021
Main public npm plugin repositoryLatest commit May 26, 2022
Public IntelliJ plugin repositoryLatest commit August 9, 2021

This evidence supports classifying the product as unavailable. It does not establish a precise date when the company or service ceased operating, so this page does not assign one.

Historical product boundaries

Reshift should not be described as Node.js-only. The public npm plugin focused on JavaScript, while the company announcement and IntelliJ plugin document Java coverage.

The company announced plans for C#, C/C++, and Python in 2021, but the reviewed public sources do not establish that those scanners shipped. They are therefore not listed as supported languages.

Historical pricing is not included. No current vendor-controlled pricing page exists, and old third-party listings are not reliable enough to publish as product pricing.

Choosing a replacement

Start with the languages and workflows Reshift covered: Java or JavaScript analysis, command-line or IDE feedback, remediation guidance, and repository integration. Then compare active tools on deployment model, analysis depth, support, and current pricing.

The SAST tools directory lists the active products currently tracked by AppSec Santa. It is safer than treating one named scanner as a universal replacement.

Historical sources

Note: Historical record. The former Reshift domain redirects to an unrelated site; the website link points to the public GitHub organization instead.

Frequently Asked Questions

What was Reshift?
Reshift was a commercial SaaS application security platform. A February 2021 company release says the platform scanned Java and added JavaScript, with vulnerability findings and corrective guidance for developers.
Is Reshift still available?
No current product endpoint was identified. The former domain redirects to an unrelated site, the npm package was last published in 2021, and the main public plugin repository has no commit after May 2022.
Was Reshift only a Node.js scanner?
No. Reshift’s 2021 launch announcement says JavaScript was added to an existing Java scanning capability. The public npm plugin targeted JavaScript, while a separate IntelliJ plugin targeted Java developers.
Can I still use the old Reshift npm plugin?
The package remains visible in the npm registry, but its documented workflow requires a Reshift account and token from endpoints that are no longer available. Do not send credentials to the former product domain.
What should replace Reshift?
Choose an active SAST product based on required languages, analysis depth, deployment, integrations, support, and budget. The AppSec Santa SAST directory lists currently tracked products without assuming one replacement fits every former Reshift user.