
sast-scan
Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool…

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

🐺 Vulfy – Fast Rust based package version scanner

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Static code analysis tool based on Elasticsearch

Coverage-based fuzzer for python applications

AST-based Python code transformation & deobfuscation framework