
scorecard
OpenSSF Scorecard - Security health metrics for Open Source

OpenSSF Scorecard - Security health metrics for Open Source

Prevents you from committing secrets and credentials into git repositories

VisualCodeGrepper - Code security scanning tool.

Automated PHP configuration auditor that scans php.ini for security misconfigurations, supports CLI and web modes, and outputs results in text, HTML,…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Validate environment variable usage in codebase

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

OWASP Thick Client Application Security Verification Standard

Apache RAT (Release Audit Tool) Gradle Plugin

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

Managing GitHub Advanced Security (GHAS) Controls at Scale

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

A macOS app to scan Xcode project files for possible security issues.

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively