
vulnhuntr
Zero shot vulnerability discovery using LLMs

Zero shot vulnerability discovery using LLMs

Go-based automation tool that scans GitHub repositories for vulnerable Next.js versions (CVE-2025-66478) and automatically creates pull requests with…

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

Go static analysis tool that checks for security issues using an AST.

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

A Chrome extension static analysis tool to help aide in security reviews.

Go CLI that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript using AST transforms, static decoding, and a goja…

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Defense Against the Shai-Hulud Supply Chain Attack

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…