
progpilot
PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Static code analysis tool based on Elasticsearch

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

VBScript & VBA source-to-source deobfuscator with partial-evaluation


client-side prototype pullution vulnerability scanner

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU


Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Vulnerability Assessment Scanner with Report Generation

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target


Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

A Bitbucket Pipe to trigger SonarCloud analysis