
DevAudit
Open-source, cross-platform, multi-purpose security auditing tool

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.


Fast and powerful SSL/TLS scanning library.

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

👮 👊 RegEx Denial of Service (ReDos) Scanner

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

Rust-powered HTTP Request Smuggling Scanner.

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Public OCI-Image (docker image) Security Checker


Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects


Create actionable data from your Vulnerability Scans

Checklist of the most important security countermeasures when designing, testing, and releasing your API

A reverse proxy like nginx, built on pingora, simple and efficient.