
StaCoAn
StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

A list of awesome penetration testing tools and resources.

Link sources to sinks in C# applications.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Static code analysis tool based on Elasticsearch

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

A static analyzer for Java, C, C++, and Objective-C

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

grep rough audit - source code auditing tool

Python Command-Line Ghidra Decompiler

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

VisualCodeGrepper - Code security scanning tool.

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…