
android-check
Static code analysis plugin for Android project. (Checkstyle, PMD)

Static code analysis plugin for Android project. (Checkstyle, PMD)

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

find hardcoded strings from source code

👮 👊 RegEx Denial of Service (ReDos) Scanner

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

UT based automated fuzz driver generation


Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

client-side prototype pullution vulnerability scanner

The Secure Coding Practices Quick-reference Guide from OWASP

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Go static analysis tool that checks for security issues using an AST.


Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool