
progpilot
PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Static code analysis tool based on Elasticsearch

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Python Command-Line Ghidra Decompiler

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

NCC Code Navigator

Checklist and tools for increasing security of Apache Airflow


BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Java utility library with patched CVE-2022-4244 vulnerability, providing common helper classes for I/O, reflection, and CLI argument parsing in…

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…