


PHP Static Analysis Tool - discover bugs in your code without running it!

An extensible multilanguage static code analyzer.

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

Bandit is a tool designed to find common security issues in Python code.

The ASN1_STRING_set() function takes an `int` length, make sure the argument is not inadvertently truncated when it is called from asn1_ex_c2i().

nodejsscan is a static security code scanner for Node.js applications.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

A static analyzer for Java, C, C++, and Objective-C

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…