
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Protect against malicious open source packages 🤖

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A vulnerability scanner for container images and filesystems

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Vulnerability Static Analysis for Containers

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

A Public Package Scanner for The Community

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

A service that analyzes docker images and scans for vulnerabilities

Trivy example module for WordPress

Detections for CVE-2021-44228 inside of nested binaries

A project security/vulnerability/risk scanning tool
