
wpBullet
Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.


Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Python Command-Line Ghidra Decompiler

AST-based Python code transformation & deobfuscation framework

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Link sources to sinks in C# applications.

The iOS Security Testing Framework

A collection of my Semgrep rules to facilitate vulnerability research.

CVE-2026-39259

解决网络安全漏洞

A CodeQL query to find CVE 2022-35737

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

Easy setup of static analysis tools for Android and Java projects.