
progpilot
PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Static code analysis tool based on Elasticsearch

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

VBScript & VBA source-to-source deobfuscator with partial-evaluation


client-side prototype pullution vulnerability scanner


Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Vulnerability Assessment Scanner with Report Generation

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool


Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

A Bitbucket Pipe to trigger SonarCloud analysis