

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Static code analysis tool based on Elasticsearch

AST-based Python code transformation & deobfuscation framework

UT based automated fuzz driver generation

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Web-based Source Code Vulnerability Scanner

Bandit is a tool designed to find common security issues in Python code.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…