
phpstan
PHP Static Analysis Tool - discover bugs in your code without running it!

PHP Static Analysis Tool - discover bugs in your code without running it!

A list of awesome penetration testing tools and resources.

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

The iOS Security Testing Framework

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

The Secure Coding Framework

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered bug bounty hunting toolkit that works with or without subscription.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

This skill helps Claude write secure code and prevent common vulnerabilities.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Linting tool for CloudFormation templates

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)