
yls
Language server for YARA rule development, providing code completion, linting, formatting, navigation, and debugging support inside IDEs.

Language server for YARA rule development, providing code completion, linting, formatting, navigation, and debugging support inside IDEs.

Batch-decompile binaries with Ghidra from the command line, generating per-function C files, callgraphs, BSim signatures, and optional SAST results…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

A static code analysis for WordPress (and PHP)

Bandit is a tool designed to find common security issues in Python code.

a static analysis tool for finding vulnerabilities in C/C++ source code


"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…