Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: code-audit (28)

Pentesting tools tagged code-audit. See all tools or the category key.

Team (best effort)

bof-detector

A simple detector of BOF vulnerabilities by source-code-level check.

code-audit Red Team

brakeman

A static analysis security vulnerability scanner for Ruby on Rails applications.

code-audit Red Team

cflow

A C program flow analyzer.

code-audit Red Team

checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images a

code-audit Red Team

cpptest

A portable and powerful, yet simple, unit testing framework for handling automated tests in C++.

code-audit Red Team

dependency-check

A tool that attempts to detect publicly disclosed vulnerabilities contained within a project's dependencies.

code-audit Red Team

detect-secrets

An enterprise friendly way of detecting and preventing secrets in code.

code-audit Red Team

devaudit

An open-source, cross-platform, multi-purpose security auditing tool targeted at developers and teams.

code-audit Red Team

githound

Find secret information in git repositories.

code-audit Red Team

horusec

Static code analysis to identify security flaws for many languages.

code-audit Red Team

local-php-security-checker

A command line tool that checks your PHP application packages with known security vulnerabilities.

code-audit Red Team

mosca

Static analysis tool to find bugs like a grep unix command.

code-audit Red Team

njsscan

A static application testing (SAST) tool that can find insecure code patterns in your node.js applications.

code-audit Red Team

phpstan

PHP Static Analysis Tool - discover bugs in your code without running it.

code-audit Red Team

pscan

A limited problem scanner for C source files

code-audit Red Team

rats

A rough auditing tool for security in source code files.

code-audit Red Team

semgrep

Lightweight static analysis for many languages.

code-audit Red Team

slither

Solidity static analysis framework written in Python 3.

code-audit Red Team

snyk

CLI and build-time tool to find and fix known vulnerabilities in open-source dependencies.

code-audit Red Team

sonar-scanner

Generic CLI tool to launch project analysis on SonarQube servers.

code-audit Red Team

spotbugs

A tool for static analysis to look for bugs in Java code.

code-audit Red Team

stoq

An open source framework for enterprise level automated analysis.

code-audit Red Team

tell-me-your-secrets

Find secrets on any machine from over 120 Different Signatures.

code-audit Red Team

whispers

Identify hardcoded secrets in static structured text.

code-audit Red Team

wpbullet

A static code analysis for WordPress (and PHP).

code-audit Red Team

wscript

Emulator/tracer of the Windows Script Host functionality.

code-audit Red Team

yasca

Multi-Language Static Analysis Toolset.

code-audit Red Team

zarn

A lightweight static security analysis tool for modern Perl Apps.

code-audit Red Team