
ApplicationInspector
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Easy setup of static analysis tools for Android and Java projects.

nodejsscan is a static security code scanner for Node.js applications.

find hardcoded strings from source code

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Sourcetrail - free and open-source interactive source explorer

AWS Serverless Security

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

NCC Code Navigator

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.