Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Static Code Analysis (SAST) | Kitploit
Categories

Static Code Analysis (SAST)

Tools for examining source code without execution to find security flaws.

Kitploit recommended

Top tools

10 selected
semgrep preview#1

semgrep

GitHubsemgrep/semgrep
16.2k5 days ago
codeql preview#2

codeql

GitHubgithub/codeql
10.1k0 days ago
sonarqube preview#3

sonarqube

GitHubsonarsource/sonarqube
11.0k17h 3m ago
infer preview#4

infer

GitHubfacebook/infer
15.7k5 days ago
bandit preview#5

bandit

GitHubpycqa/bandit
8.2k10 days ago
gosec preview#6

gosec

GitHubsecurego/gosec
8.9k1 day ago
bearer preview#7

bearer

GitHubbearer/bearer
2.7k16 days ago
horusec preview#8

horusec

GitHubzupit/horusec
1.3k3 years ago
ApplicationInspector preview#9

ApplicationInspector

GitHubmicrosoft/applicationinspector
4.4k13 days ago
njsscan preview#10

njsscan

GitHubajinabraham/njsscan
43629 days ago
NewestRelevanceMost popularRecently updated
153 results
sast-scan-action preview

sast-scan-action

GitHuboffensive360/sast-scan-action

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

vulnerability-scannersstatic-code-analysiscode-analysis+4
1 month ago
mcp-server preview

mcp-server

GitHuboffensive360/mcp-server

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

static-code-analysisvulnerability-analysiscode-analysis+3
1 month ago
enforcement-coverage preview

enforcement-coverage

GitHubarian-gogani/enforcement-coverage

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

static-code-analysisvulnerability-analysiscode-analysis+3
116 days ago
Agentic-Bug-Hunter preview

Agentic-Bug-Hunter

GitHubawarexone/agentic-bug-hunter

AI-powered bug bounty hunting toolkit that works with or without subscription.

reconnaissancevulnerability-scannersweb-vulnerability-scanners+8
4.7k4 days ago
agentic-radar preview

agentic-radar

GitHubsplx-ai/agentic-radar

A security scanner for your LLM agentic workflows

vulnerability-scannersstatic-code-analysisdynamic-code-analysis+5
1.0k9 months ago
cfn_nag preview

cfn_nag

GitHubstelligent/cfn_nag

Linting tool for CloudFormation templates

static-code-analysisconfiguration-auditingcloud-security+3
1.3k2 years ago
static-code-analysis-helper preview

static-code-analysis-helper

GitHubosmankandemir/static-code-analysis-helper

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

static-code-analysisvulnerability-analysiscode-analysis+1
336 months ago
contrast preview

contrast

GitHubcontrastsecurity/contrast

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

cloud-infrastructure-securityvulnerability-scannersstatic-code-analysis+6
202 months ago
static-analysis preview

static-analysis

GitHubanalysis-tools-dev/static-analysis

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

static-analysisstatic-code-analysisvulnerability-analysis+5
14.8k1 day ago
kubesec preview

kubesec

GitHubcontrolplaneio/kubesec

Security risk analysis for Kubernetes resources

cloud-infrastructure-securitydefensive-toolsstatic-analysis+7
1.5k3 months ago
semgrep-rules preview

semgrep-rules

GitHubsemgrep/semgrep-rules

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

static-analysisvulnerability-scannersstatic-code-analysis+3
1.3k1 month ago
modelaudit preview

modelaudit

GitHubpromptfoo/modelaudit

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

static-analysisstatic-code-analysisvulnerability-analysis+8
701 day ago
sonarqube preview

sonarqube

GitHubsonarsource/sonarqube

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

static-analysisstatic-code-analysisvulnerability-analysis+2
11.0k17h 3m ago
kube-linter preview

kube-linter

GitHubstackrox/kube-linter

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

cloud-infrastructure-securitystatic-analysiscontainer-security+6
3.5k7h 59m ago
nullorigin preview

nullorigin

GitHubrakib-nyc/nullorigin

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

static-code-analysisweb-proxies-interceptionsteganography+4
423 days ago
cve-2020-9373-netgear-r6400 preview

cve-2020-9373-netgear-r6400

GitHublimingxi6/cve-2020-9373-netgear-r6400

解决网络安全漏洞

embedded-systems-securityiot-securitystatic-code-analysis+6
25 days ago
codeql preview

codeql

GitHubgithub/codeql

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

static-code-analysisvulnerability-analysiscode-analysis+1
10.1k0 days ago
actions-secrets preview

actions-secrets

GitHubgmh5225/actions-secrets

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

static-code-analysiscode-analysisdevsecops+1
3 years ago
Previous12…9Next