
phpstan
PHP Static Analysis Tool - discover bugs in your code without running it!

PHP Static Analysis Tool - discover bugs in your code without running it!

Bandit is a tool designed to find common security issues in Python code.

An extensible multilanguage static code analyzer.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Tool for reverse engineering of Angular applications

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

UT based automated fuzz driver generation


Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

The Secure Coding Practices Quick-reference Guide from OWASP

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Go static analysis tool that checks for security issues using an AST.


Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.