insider

Security analyzer

A tool that analyzes source code to identify security vulnerabilities and provides reporting on compliance with the OWASP Top 10

Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C#, and Javascript (Node.js).

GitHub

519 stars
18 watching
80 forks
Language: Go
last commit: over 4 years ago
Linked from 1 awesome list

androidandroid-securityclicsharpdotnetinsideriosios-securityjavascriptkotlinmavennodejsowaspsastsecurity-automationsecurity-scannersecurity-toolsstatic-analysisstatic-analyzerswift

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
flatt-security/shishoA tool that analyzes code for security vulnerabilities and provides feedback to developers369
bearer/bearerA tool for discovering and prioritizing security risks in software code2,112
sonarsource/sonar-javaAnalyzes Java code quality and security issues to help developers write cleaner code1,144
dev-lu/osint_toolkitA web application combining various security analysis tools and services into one platform526
zupit/horusecIdentifies security flaws in software projects through static code analysis1,154
tcosolutions/betterscanA toolchain that scans source code and infrastructure IaC for security risks and provides a unified report.831
theresafewconors/sootyA tool designed to aid cybersecurity analysts in automating routine checks and enhancing their workflow1,364
eth-sri/securifyA security scanner for Ethereum smart contracts219
doyensec/electronegativityAn Electron application security analysis tool that identifies misconfigurations and potential weaknesses.980
eth-sri/securify2An automated security scanner for Ethereum smart contracts589
microsoft/infersharpA tool that analyzes C# code for potential issues such as null pointer dereferences and resource leaks to help detect security vulnerabilities.737
nodesecure/js-x-rayA tool that scans JavaScript code for potential security vulnerabilities and patterns229
security-code-scan/security-code-scanDetects vulnerabilities in C# and VB.NET code942
secdec/attack-surface-detector-burpIdentifies web app endpoints and parameters to help detect vulnerabilities98
albuch/sbt-dependency-checkAutomatically monitors dependencies for known vulnerabilities and generates reports on security issues266