Showing 23 of 59 projects
A static analysis security scanner for Ruby web applications, supporting Rails, Sinatra, and Padrino frameworks.
A PHP_CodeSniffer ruleset that detects security vulnerabilities and weaknesses in PHP code, including Drupal 7.
A collection of GitHub Actions for Snyk to check projects for vulnerabilities across multiple languages and tools.
A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.
A blackbox security profiling tool for Android that hooks and analyzes security-sensitive APIs at runtime.
Open-source static analysis tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and AI-generated regressions.
A Visual Studio extension for real-time .NET secure code analysis that displays vulnerabilities as compiler warnings.
A secure, extensible command-line Android APK vulnerability analyzer written in Rust for automated security testing.
A fuzzer for Linux kernel drivers that combines interface recovery via LLVM analysis with a fuzzing engine to find security vulnerabilities.
A static security scanner for PHP code that identifies potential vulnerabilities without executing the code.
A static application security testing (SAST) tool for PHP that detects vulnerabilities like XSS through taint analysis.
A security scanning CLI tool that detects vulnerabilities, secrets, and outdated dependencies across multiple programming languages.
A static analysis tool for Android applications that detects security vulnerabilities through inter-procedure and intra-procedure analysis.
A tool to scan projects for regexes vulnerable to catastrophic backtracking (REDOS) through static extraction, detection, and validation.
A trustworthy ReDoS (Regular Expression Denial of Service) checker for identifying vulnerable regex patterns.
A static and symbolic analysis tool for finding memory safety bugs in browser code and other software.
Roslyn analyzers for detecting security vulnerabilities in .NET applications during development.
A browser emulation tool that detects exploits targeting browser and browser plugin vulnerabilities by analyzing various file types.
A dependency-aware GraphQL API fuzzing tool that automatically generates and executes security tests based on schema introspection.
A static analysis tool that spots security vulnerabilities in PostgreSQL extension scripts and SQL code.
A framework for using AFL to fuzz web applications and detect SQL/command injection vulnerabilities.
A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.
A static analyzer for Teal (Algorand Smart Contracts) that detects vulnerabilities and visualizes contract structure.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.