
recheck
Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

UT based automated fuzz driver generation


CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Vulnerability Patterns Detector for C# and VB.NET

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

A static code analysis for WordPress (and PHP)

RIPS - A static source code analyser for vulnerabilities in PHP scripts

👮 👊 RegEx Denial of Service (ReDos) Scanner

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…