Every check is the full 22, and repositories already known to be malicious stay blocked even past your limit. Paid plans lift the cap and add the rest — more machines, the stats board, the live ticker, the MCP server, Claude Code plugin and Claude skill for AI agents, and deep scans of the files themselves.
Every developer, to start
1 device · 10 repo checks in your first 14 days
A developer with more than one machine
3 devices · billed yearly
Checkout opens shortly. Nothing to pay yet.
Personal, plus the files themselves read in a sandbox
3 devices · 20 deep scans a year
Deep scans are live. This tier opens as soon as checkout does.
3–5 developers · coming
3–5 seats on one invoice — not on sale yet
Buying for a team today? Personal, one per developer — same protection, no seat to wait for.
One credit is one repository read in an isolated sandbox — the static engines plus Claude on the risky files — and the scan's verdict becomes the verdict. Credits never expire, and the Premium tier includes 20 a year. A clean scan is not proof of safety; it is every engine finding nothing it recognises, and the result says exactly which engines ran. Your AI agents can spend them too — through the MCP server or the Claude Code plugin, one scan per call and only after you say yes to that call, at most five agent-started scans a day per account. A repeat of the same repository within 15 minutes returns the same result and costs nothing.
Deep scans are live — the packs go on sale as soon as checkout opens.
Choosing a different plan moves the subscription you already have — it never starts a second one. Moving up is charged pro rata whenever you do it: you pay only the difference on the part of the period you have not used, and your renewal date stays where it was. Personal to Premium the day after paying annually is $10, not $39.
Moving down inside the first 30 days of an annual period (7 days of a monthly one) is credited pro rata to your balance. After that it takes effect without a refund — the full wording.
Free covers 10 distinct repositories within 14 days of registering — each one the full 22 checks. Two limits, whichever comes first: the ten repositories, or the thirty days. It does not reset month to month. Checking the same repository twice never counts twice.
Past the limit, RepoGates does not go quiet and it does not pretend. Repositories already known to be malicious are still blocked, because that costs us nothing and letting known malware through to someone who has not paid would be indefensible. For anything else you are told plainly that it was not checked, and you choose: upgrade, or continue at your own risk. That choice is recorded either way.
If a subscription lapses, RepoGates drops back to the free tier and keeps gating downloads. Your trial does not restart — new repositories are no longer assessed — but it never switches protection off for non-payment. Nobody should be less safe because their card expired.
The security column is identical on every row that matters. That is the point.
| Free | Personal | Premium | Team | |
|---|---|---|---|---|
| Protection | ||||
| Download gate on GitHub | ✓ | ✓ | ✓ | ✓ |
| Repository checks | 10 in first 14 days | unlimited | unlimited | unlimited |
| All 22 trust checks | ✓ | ✓ | ✓ | ✓ |
| Campaign blocklist | ✓ | ✓ | ✓ | ✓ |
| AI-provenance detection (C22) | ✓ | ✓ | ✓ | ✓ |
| Insight | ||||
| Quick-stats board | — | ✓ | ✓ | ✓ |
| Live security ticker | — | ✓ | ✓ | ✓ |
| Owner and maintainer scores | — | ✓ | ✓ | ✓ |
| MCP server, Claude Code plugin and Claude skill for AI agents | — | ✓ | ✓ | ✓ |
| Personal API tokens | — | up to 5 | up to 5 | up to 5 |
| Reading the code itself | ||||
| Deep scans included | — | — | 20 a year | — |
| Buy scan packs | — | ✓ | ✓ | ✓ |
| Scan report, SARIF export | — | ✓ | ✓ | ✓ |
| Agent-started scans, with your yes | — | 5 a day | 5 a day | 5 a day |
| Machines and people | ||||
| Devices per person | 1 | 3 | 3 | 3 |
| Billed together, one invoice | — | — | — | ✓ |
| Seats | 1 | 1 | 1 | 3–5, coming |
Chrome and Edge ship a new major version every four weeks. Each one can break a blocking download listener, and each one has to be tested against. That work is constant, and it is what keeps the free tier working for everyone. Personal pays for it.
New repositories stop being assessed and RepoGates says so — it does not go quiet and let things through as though they were fine. Known malware is still blocked. For anything else you choose: upgrade, or continue unchecked. Either choice is recorded.
You go back to the free tier — the gate keeps working and known malware stays blocked; new repositories are no longer assessed. You lose the board, the ticker, the MCP server and plugin, and the extra devices. You do not lose the gate. Switching protection off over a card expiry would be a strange thing for a security product to do.
Each browser profile that installs RepoGates registers a random id — not a hardware fingerprint. You can see your devices and remove one at any time to free a slot.
No, and no browser extension can — it cannot see other processes. RepoGates gates browser downloads, which is how the FakeGit campaign actually delivered its payloads. It does not see git clone, package managers or curl — outside Claude Code with the RepoGates plugin, whose hook refuses a clone or install that names a blocked repository on the command line, before it runs. A registry package named on that line — npm install express, pip install flask — is resolved through npm or PyPI to the source repository it declares; direct dependencies only. The hook sees Bash tool calls in that one client; the MCP server covers AI agents that choose to ask, and the same skill in Claude.ai and Cowork asks before a clone with no hook to refuse. The full coverage table is here.