Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
static-analysis — Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code quality. | Kitploit
Tools/GitHubGitHub/analysis-tools-dev/static-analysis
Static AnalysisStatic Code Analysis (SAST)Vulnerability AnalysisCode AnalysisDevSecOpsPapers & ResearchLearning & EducationCurated ResourcesTop in Curated Resources #13

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Top in Learning & Education #14
Top in Papers & Research #18
GitHubanalysis-tools-dev/static-analysis

static-analysis

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code quality.

View RepositoryWebsite
14.8k1.5k10111 days agoReviewed by Kitploit
Share
Analysis Tools Website

This repository lists static analysis tools for all programming languages, build tools, config files and more. The focus is on tools which improve code quality such as linters and formatters. The official website, analysis-tools.dev is based on this repository and adds rankings, user comments, and additional resources like videos for each tool.

Website CI Links

Sponsors

This project would not be possible without the generous support of our sponsors.

Pixee CodeRabbit Semgrep Offensive360

If you also want to support this project, head over to our GitHub Sponsors page.

Meaning of symbols

  • ©️ stands for proprietary software. All other tools are open source.
  • ℹ️ indicates that the community does not recommend the tool for new projects. The icon links to the discussion issue.
  • ⚠️ means that the tool was not updated for more than one year, or its repository was archived.

Pull requests are very welcome!

Also check out the sister project, awesome-dynamic-analysis.

Table of Contents

Programming Languages

ABAPErlangPL/SQL
AdaF#Perl
AssemblyFortranPython
AwkGoR
CGroovyRego
C#HaskellRuby
C++HaxeRust
ClojureJavaSQL
CoffeeScriptJavaScriptScala
ColdFusionJuliaShell
CrystalKotlinSwift
DartLuaTcl
DelphiMATLABTypeScript
DlangNimVerilog/SystemVerilog
ElixirOcamlVim Script
ElmPHPWebAssembly

Multiple Languages

Other

Show Other
.envEmbedded Ruby (a.k.a. ERB, eRuby)Protocol Buffers
AI-generated codeGherkinPuppet
AnsibleHTMLRails
ArchiveJSONSecurity/SAST
Azure Resource ManagerKubernetesSmart Contracts
BinariesLaTeXSupport
Build toolsLaravelTemplate-Languages
CSS/SASS/SCSSMakefilesTerraform
Config FilesMarkdownTranslation
Configuration ManagementMetalinterUses LLM/model
ContainersMobileVue.js
Continuous IntegrationNixWriting
DenoNode.jsXML
DockerfilePackagesYAML
EmbeddedPrometheusgit

Programming Languages

ABAP

  • abaplint — Linter for ABAP, written in TypeScript.

  • abapOpenChecks — Enhances the SAP Code Inspector with new and customizable checks.

Ada

  • Polyspace for Ada ©️ — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in source code.

  • SPARK ©️ — Static analysis and formal verification toolset for Ada.

Assembly

  • STOKE ⚠️ — A programming-language agnostic stochastic optimizer for the x86_64 instruction set. It uses random search to explore the extremely high-dimensional space of all possible program transformations.

Awk

  • gawk --lint — Warns about constructs that are dubious or nonportable to other awk implementations.

C

  • Astrée ©️ — Astrée automatically proves the absence of runtime errors and invalid con­current behavior in C/C++ applications. It is sound for floating-point computations, very fast, and exceptionally precise. The analyzer also checks for MISRA/CERT/CWE/Adaptive Autosar coding rules and supports qualification for ISO 26262, DO-178C level A, and other safety standards. Jenkins and Eclipse plugins are available.

  • CBMC — Bounded model-checker for C programs, user-defined assertions, standard assertions, several coverage metric analyses.

  • clang-tidy — Clang-based C++ linter tool with the (limited) ability to fix issues, too.

  • clazy — Qt-oriented static code analyzer based on the Clang framework. clazy is a compiler plugin which allows clang to understand Qt semantics. You get more than 50 Qt related compiler warnings, ranging from unneeded memory allocations to misusage of API, including fix-its for automatic refactoring.

  • CMetrics ⚠️ — Measures size and complexity for C files.

Download Tool