
njsscan
Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

A security scanner for your LLM agentic workflows

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

The Secure Coding Framework

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Open-source, cross-platform, multi-purpose security auditing tool

VisualCodeGrepper - Code security scanning tool.

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

The iOS Security Testing Framework