
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Sourcetrail - free and open-source interactive source explorer

Easy setup of static analysis tools for Android and Java projects.

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Checklist and tools for increasing security of Apache Airflow

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Static code analysis plugin for Android project. (Checkstyle, PMD)

The Secure Coding Practices Quick-reference Guide from OWASP

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

CVE-2026-39259

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

A static analyzer for Java, C, C++, and Objective-C

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…