
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Linting tool for CloudFormation templates

Tool for reverse engineering of Angular applications

a static analysis tool for finding vulnerabilities in C/C++ source code

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

CLI tool to scan codebases for quantum-vulnerable cryptography

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

A static analysis tool for securing Go code

Open-source, cross-platform, multi-purpose security auditing tool


Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

A static analyzer for Java, C, C++, and Objective-C