
route-sixty-sink
Link sources to sinks in C# applications.

Link sources to sinks in C# applications.

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Static code analysis tool based on Elasticsearch



Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

A Bitbucket Pipe to trigger SonarCloud analysis

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered bug bounty hunting toolkit that works with or without subscription.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

grep rough audit - source code auditing tool

Curated Ghidra scripts to automate reverse engineering and vulnerability analysis: locate insecure functions, extract decompiler pseudocode, fix…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…