
static-code-analysis-helper
Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

A Bitbucket Pipe to trigger SonarCloud analysis

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

解决网络安全漏洞

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Link sources to sinks in C# applications.

AWS Serverless Security


Open-source, cross-platform, multi-purpose security auditing tool

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.