
kube-score
Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Python Command-Line Ghidra Decompiler

A list of awesome penetration testing tools and resources.

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Vulnerability Patterns Detector for C# and VB.NET

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

A static code analysis for WordPress (and PHP)

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

find hardcoded strings from source code

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

👮 👊 RegEx Denial of Service (ReDos) Scanner

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…