
gitleaks
Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Security-focused static analysis for the Phoenix Framework

Automatic SSTI detection tool with interactive interface

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.


Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.