
lightweight_static_analysis
Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

A static analysis tool for securing Go code

grep rough audit - source code auditing tool

The iOS Security Testing Framework

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

A static code analysis for WordPress (and PHP)

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

The Secure Coding Practices Quick-reference Guide from OWASP