
crypto-scanner
CLI tool to scan codebases for quantum-vulnerable cryptography

CLI tool to scan codebases for quantum-vulnerable cryptography

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

A Bitbucket Pipe to trigger SonarCloud analysis

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Bookea-tu-Mesa is vulnerable to SQL Injection

Link sources to sinks in C# applications.

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

grep rough audit - source code auditing tool

Static code analysis tool based on Elasticsearch

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Go static analysis tool that checks for security issues using an AST.

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

C++ python bytecode disassembler and decompiler

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Batch-decompile binaries with Ghidra from the command line, generating per-function C files, callgraphs, BSim signatures, and optional SAST results…