
shiro-check
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268

扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268

查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293


Checklist of the most important security countermeasures when designing, testing, and releasing your API

Slides for Developing Secure Software in 2024 at CanSecWest

LLM powered fuzzing via OSS-Fuzz.


Rust-powered HTTP Request Smuggling Scanner.


AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

GitHub Actions workflow sandbox for CVE-2025-55192 reproduction


Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

👮 👊 RegEx Denial of Service (ReDos) Scanner