
mininode
Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Traces user inputs to detect injection vulnerabilities in Java methods via JDWP and Frida, identifying potential command and SQL injection points.

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

APKinspector is a powerful GUI tool for analysts to analyze the Android applications.

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Go package that checks if RSA keys are vulnerable to ROCA / CVE-2017-15361

A tool to hunt for credentials in github wild AKA git*hunt

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Patched Vue 2.7.16 template compiler with fixes for CVE‑2024‑6783 and CVE-2024-9506

C-based detection tool for CVE-2017-2793, enabling identification and analysis of the specific vulnerability in affected systems.

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Identify hardcoded secrets in static structured text

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.