
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Tool for reverse engineering of Angular applications

A security scanner for your LLM agentic workflows

Vulnerability Patterns Detector for C# and VB.NET

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

a static analysis tool for finding vulnerabilities in C/C++ source code

A static code analysis for WordPress (and PHP)

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

Specialized reasoning LLM for source-code vulnerability detection in C/C++ and Python, with dataset construction, SFT/DPO training, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.