
DakshSCRA
Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

PHP Static Analysis Tool - discover bugs in your code without running it!

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…


UT based automated fuzz driver generation



CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security