
DakshSCRA
Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Python Command-Line Ghidra Decompiler

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

The Secure Coding Framework


VBScript & VBA source-to-source deobfuscator with partial-evaluation

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Linting tool for CloudFormation templates

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Checklist and tools for increasing security of Apache Airflow

Static code analysis tool based on Elasticsearch

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…