
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

find hardcoded strings from source code

A static analyzer for Java, C, C++, and Objective-C

PHP Static Analysis Tool - discover bugs in your code without running it!

AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Bandit is a tool designed to find common security issues in Python code.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

A static analysis tool for securing Go code

grep rough audit - source code auditing tool

Tool for reverse engineering of Angular applications

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.