
bandit
Bandit is a tool designed to find common security issues in Python code.

Bandit is a tool designed to find common security issues in Python code.

A static code analysis for WordPress (and PHP)

A security scanner for your LLM agentic workflows

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

nodejsscan is a static security code scanner for Node.js applications.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

C++ python bytecode disassembler and decompiler

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice