
grepmarx
A source code static analysis platform for AppSec enthusiasts.

A source code static analysis platform for AppSec enthusiasts.

Burp Extension for collaboration in Faraday

OWASP Security Culture repository

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark


AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

InSpec-based compliance profile for auditing Linux system hardening against security baselines, ensuring consistent configuration across…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

A privacy and security engineering toolkit: Discover, understand, pseudonymize, anonymize, encrypt and securely share sensitive and personal data:…

server security auditor scanning Apache, Nginx, and IIS configurations with AI-powered hardening guides and professional reporting.

OpenSSF Scorecard - Security health metrics for Open Source

Open Source Cloud Native Application Protection Platform (CNAPP)

GitHub App to set and enforce security policies

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…