
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Easy setup of static analysis tools for Android and Java projects.

The Secure Coding Practices Quick-reference Guide from OWASP

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Static code analysis plugin for Android project. (Checkstyle, PMD)

CVE-2026-39259

Sourcetrail - free and open-source interactive source explorer

Checklist and tools for increasing security of Apache Airflow

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)