
wpBullet
Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

Modular static analysis tool to extract hardcoded strings from source code, supporting 20+ languages with comment-aware tokenization for developers…

Pluggable vulnerability assessment and management platform that orchestrates static and dynamic analysis scanners for web, mobile, network, and code,…

AWS Lambda auditing tool for asset visibility, statistical analysis, dependency mapping, and security configuration checks across serverless…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

PHP Static Analysis Tool - discover bugs in your code without running it!

Multi-language SAST tool that scans source code, Git history, and IaC for security flaws, secrets, and misconfigurations, integrating into CI/CD…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Static code analysis tool based on Elasticsearch

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Go static analysis tool that checks for security issues using an AST.

Interactive Python call graph navigator for tracing code paths from user input to dangerous patterns, designed for security auditing and code…

Detects JavaScript libraries and Node.js modules with known vulnerabilities via CLI, Chrome extension, and CI/CD plugin integrations for web…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…