
cq
Source code security scanner for expert code review; emits file:line findings in plain text, designed for fast manual triage and filtering with…

Source code security scanner for expert code review; emits file:line findings in plain text, designed for fast manual triage and filtering with…

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

A static analyzer for Java, C, C++, and Objective-C

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

A list of awesome penetration testing tools and resources.

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…


Vulnerability Patterns Detector for C# and VB.NET

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

A static code analysis for WordPress (and PHP)

RIPS - A static source code analyser for vulnerabilities in PHP scripts

👮 👊 RegEx Denial of Service (ReDos) Scanner

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Scans Python codebases for the tarfile extraction vulnerability (CVE-2007-4559) using AST parsing, categorizing findings by confidence to prioritize…

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…