
bandit
Bandit is a tool designed to find common security issues in Python code.

Bandit is a tool designed to find common security issues in Python code.

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

A static code analysis for WordPress (and PHP)

PHP Static Analysis Tool - discover bugs in your code without running it!

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Linting tool for CloudFormation templates

A list of awesome penetration testing tools and resources.

The Secure Coding Framework

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…