
static-code-analysis-helper
Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…


jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Go static analysis tool that checks for security issues using an AST.

Bookea-tu-Mesa is vulnerable to SQL Injection

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.


Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Tool for reverse engineering of Angular applications

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…