
RiskAssessmentFramework
OWASP Static Application Security Testing (SAST) tool for analyzing code quality and vulnerabilities, designed for DevSecOps integration to help…

OWASP Static Application Security Testing (SAST) tool for analyzing code quality and vulnerabilities, designed for DevSecOps integration to help…

Modular static analysis tool to extract hardcoded strings from source code, supporting 20+ languages with comment-aware tokenization for developers…

A static analyzer for Java, C, C++, and Objective-C

PHP Static Analysis Tool - discover bugs in your code without running it!

AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool that inspects Go source code for security vulnerabilities using AST, SSA, and taint analysis, with CI/CD integration and CWE…

AST-based security linter that scans Python code for common vulnerabilities by running plugins against parsed syntax trees, generating detailed…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Static code analysis tool for Kubernetes object definitions that scores YAML/Helm charts for security, reliability, and best practices, with CI/CD…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A static analysis tool for securing Go code

grep rough audit - source code auditing tool

Tool for reverse engineering of Angular applications

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Multi-language SAST tool that scans source code, Git history, and IaC for security flaws, secrets, and misconfigurations, integrating into CI/CD…

Linting tool for CloudFormation templates