

Bandit is a tool designed to find common security issues in Python code.

A static code analysis for WordPress (and PHP)

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Linting tool for CloudFormation templates

The Secure Coding Framework

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

PHP Static Analysis Tool - discover bugs in your code without running it!

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

A list of awesome penetration testing tools and resources.

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

CLI tool to scan codebases for quantum-vulnerable cryptography

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.