
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

PHP Static Analysis Tool - discover bugs in your code without running it!

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Bandit is a tool designed to find common security issues in Python code.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

grep rough audit - source code auditing tool

Vulnerability Patterns Detector for C# and VB.NET

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

A static code analysis for WordPress (and PHP)