


OpenSSF Scorecard - Security health metrics for Open Source

Prevents you from committing secrets and credentials into git repositories

VisualCodeGrepper - Code security scanning tool.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Automated PHP configuration auditor that scans php.ini for security misconfigurations, supports CLI and web modes, and outputs results in text, HTML,…

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

Octoscan is a static vulnerability scanner for GitHub action workflows.

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

All-in-one tool for managing vulnerability reports from AppSec pipelines

Validate environment variable usage in codebase

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

OWASP Thick Client Application Security Verification Standard

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

Apache RAT (Release Audit Tool) Gradle Plugin

Managing GitHub Advanced Security (GHAS) Controls at Scale