Back to updates
New releaseJul 30, 2026

opentaint rules/v0.3.0

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and async code. AI-agent ready with deterministic rule replay. Open-source alternative to Semgrep Pro and CodeQL.

Share

OpenTaint

The open source taint analysis engine for the AI era

Formal taint analysis for application security — finds what AST-pattern matchers miss, lets LLM agents enact rules from vulnerabilities, scales where neither can alone.

GitHub release License: Apache 2.0 Go Version Discord

English | 简体中文 | 繁體中文 | 한국어 | Deutsch | Español | Français | Italiano | Dansk | 日本語 | Polski | Русский | Bosanski | العربية | Norsk | Svenska | Português (Brasil) | ไทย | Türkçe | Українська | বাংলা | हिन्दी | Ελληνικά | Tiếng Việt | Bahasa Indonesia

OpenTaint taint analysis demo

Supported technologies and integrations

Java     Kotlin     Spring     GitHub      GitLab

The most thorough taint analysis engine for Spring apps

Roadmap

Python     Go     C#     JavaScript     TypeScript

Categories