
apkleaks
Scanning APK file for URIs, endpoints & secrets.

Scanning APK file for URIs, endpoints & secrets.

Android security insights in full spectrum.

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

Source code for the Binaries of OWASP WrongSecrets

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

Mobile Application Vulnerability Detection

Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.

StepSecurity owned org for analyzing compromised packages

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

GitHub Action that scans ML model files for malicious code and security vulnerabilities

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

🛡️ One-command scanner for CVE-2026-45321 — TanStack npm supply-chain attack