
infer
A static analyzer for Java, C, C++, and Objective-C

A static analyzer for Java, C, C++, and Objective-C

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

PHP Static Analysis Tool - discover bugs in your code without running it!

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Bandit is a tool designed to find common security issues in Python code.


An extensible multilanguage static code analyzer.

C++ python bytecode disassembler and decompiler

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

OSWE, OSEP, OSED, OSEE

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Curated catalog of Solidity smart contract vulnerability patterns with categorized examples, prevention methods, and LLM-optimized references for…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…