
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Prevents you from committing secrets and credentials into git repositories

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

A static code analysis for WordPress (and PHP)

Python script to scan Git repos for interesting strings

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Shell-based exploit for CVE-2018-11235, a remote code execution vulnerability in Git submodules. Enables testing and validation of the flaw in…

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

A static analysis security vulnerability scanner for Ruby on Rails applications

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Pluggable linting tool to prevent committing credential.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…