
hardcodes
find hardcoded strings from source code

find hardcoded strings from source code

Detours implementation (x64/x86) which used only ntdll import

OWASP Secure Agent Playbook Project

The Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments

Neto | A tool to analyse browser extensions

Static analysis of wordpress plugins

Obfuscates Java source code to protect against reverse engineering, decompilation, and IP theft. Renames variables/methods, encrypts strings, and…

OWASP Thick Client Application Security Verification Standard

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

NCC Code Navigator

Select Bugs From Binary Where Pattern Like CVE-1337-Days

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Detect exposed API keys on GitHub commits.

AST-based Python code transformation & deobfuscation framework

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

CVE-2025-31324, SAP Exploit
