
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

find hardcoded strings from source code

A static analyzer for Java, C, C++, and Objective-C

PHP Static Analysis Tool - discover bugs in your code without running it!

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Bandit is a tool designed to find common security issues in Python code.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

A static analysis tool for securing Go code

grep rough audit - source code auditing tool

Vulnerability Patterns Detector for C# and VB.NET

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

a static analysis tool for finding vulnerabilities in C/C++ source code

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…