
"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code review in Web Application Developing or Source Code Analysis processes.
"Sucosh" is an automated Source Code vulnerability scanner(SAST) and assessment framework for Python(Flask-Django) & NodeJs capable of performing code review in Web Application Developing or Source Code Analysis processes.It’s can detect a lot of vulnerability(RCE,SSTI,Insecure Deserilisation,SSRF,SQLI,CSRF etc.) in given source code.For now, only the detection modules of python(flask,django) and nodejs(express js.) languages are finished. In the future, specific detection functions will be written for php (Laravel, Codeigniter), .NET, Go and other languages.
python3 sucosh.py -p <entercodepath>

Python
Node Js.
Other Languages and Frameworks
RCE
LFI
SSTI
SSRF
CSRF
Secret Detection
SQLI
CVE
XSS
Reflected
Stored
DOM
Custom Rule Sets
** To Do Developer Teams**
Thanks goes to these wonderful people :