
progpilot
PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Go static analysis tool that checks for security issues using an AST.

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

CLI tool that scans codebases for high-entropy lines to detect potential secrets, with customizable file extension and top-N filtering.

A tool that automatically creates fuzzing harnesses based on a library

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Vimana is an experimental security tool that aims to provide resources for auditing Python web applications.

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…