
Creosote
Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Vulnerability Patterns Detector for C# and VB.NET

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…


Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

grep rough audit - source code auditing tool

Go static analysis tool that checks for security issues using an AST.

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…