
flawfinder
a static analysis tool for finding vulnerabilities in C/C++ source code

a static analysis tool for finding vulnerabilities in C/C++ source code

A list of awesome penetration testing tools and resources.

The Secure Coding Framework

Link sources to sinks in C# applications.

A static analyzer for Java, C, C++, and Objective-C

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

PHP Static Analysis Tool - discover bugs in your code without running it!

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

A collection of my Semgrep rules to facilitate vulnerability research.

This skill helps Claude write secure code and prevent common vulnerabilities.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

RIPS - A static source code analyser for vulnerabilities in PHP scripts