
gradle-static-analysis-plugin
Easy setup of static analysis tools for Android and Java projects.

Easy setup of static analysis tools for Android and Java projects.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

nodejsscan is a static security code scanner for Node.js applications.

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

find hardcoded strings from source code

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

NCC Code Navigator

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Sourcetrail - free and open-source interactive source explorer

AWS Serverless Security