
JShunter
jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

PHP Static Analysis Tool - discover bugs in your code without running it!

a static analysis tool for finding vulnerabilities in C/C++ source code

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A list of awesome penetration testing tools and resources.

Bandit is a tool designed to find common security issues in Python code.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Link sources to sinks in C# applications.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

grep rough audit - source code auditing tool

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Static code analysis tool based on Elasticsearch

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice