
bandit
Bandit is a tool designed to find common security issues in Python code.

Bandit is a tool designed to find common security issues in Python code.

C++ python bytecode disassembler and decompiler

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Python Command-Line Ghidra Decompiler

AST-based Python code transformation & deobfuscation framework

Specialized reasoning LLM for source-code vulnerability detection in C/C++ and Python, with dataset construction, SFT/DPO training, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

A static code analysis for WordPress (and PHP)

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…