
GitLeaks
Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…

Go-based automation tool that scans GitHub repositories for vulnerable Next.js versions (CVE-2025-66478) and automatically creates pull requests with…

Software composition analysis tool that detects publicly disclosed vulnerabilities in project dependencies using CPE matching, generating detailed…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Static code analysis tool based on Elasticsearch

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

VisualCodeGrepper - Code security scanning tool.

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

Go CLI that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript using AST transforms, static decoding, and a goja…

🧬 Extract and analyze contributors info from git repos

Java bytecode analyzer customizable via JSON rules

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances