
DevAudit
Open-source, cross-platform, multi-purpose security auditing tool

A list of awesome penetration testing tools and resources.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

PHP Static Analysis Tool - discover bugs in your code without running it!

Bandit is a tool designed to find common security issues in Python code.

grep rough audit - source code auditing tool

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Static code analysis tool based on Elasticsearch

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Go static analysis tool that checks for security issues using an AST.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool