
deptrust
CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Pillage filesystems for sensitive information with Go 🔍

「🔑」A tool used to hunt down API key leaks in JS files and pages

A vulnerability scanner for container images and filesystems

A tool for secrets management, encryption as a service, and privileged access management

A tool to scan Kubernetes cluster for risky permissions

A terminal based tool for managing secrets with both tui and cli support

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Simple and flexible tool for managing secrets

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.