
fad-checker
Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

A macOS app to scan Xcode project files for possible security issues.

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

VisualCodeGrepper - Code security scanning tool.

Octoscan is a static vulnerability scanner for GitHub action workflows.

ngxray — nginx config security scanner

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

CVE-2026-42533 Nginx

OWASP Thick Client Application Security Verification Standard

Apache RAT (Release Audit Tool) Gradle Plugin

This is an OpenSSL Vulnerability Detection Script for CVE-2022-2274

Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis.…

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

cve-2025-4615 poc & deep dive

I have created AegisJava, a tool to fix (detect and mitigate) CVE-2025-30749.