Penetration testing commands for code analysis

NameDescriptionCodePriceTags
APKHuntStatic code analysis for Android apps that is based on the OWASP MASVS frameworkhttps://github.com/Cyber-Buddy/APKHuntFreecode_analysis
BrakemanStatic analysis security vulnerability scanner for Ruby on Rails applicationshttps://github.com/presidentbeef/brakemanFreecode_analysis
JoernCode analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphshttps://github.com/joernio/joernFreecode_analysis
APKLeaksScanning APK file for URIs, endpoints and secretshttps://github.com/dwisiswant0/apkleaksFreecode_analysis
BearerStatic application security testing tool that helps discover, filter, and prioritize security risks and vulnerabilitieshttps://github.com/bearer/bearerFreecode_analysis
DawnscannerSstatic analysis security scanner for ruby written web applications; supports Sinatra, Padrino and Ruby on Rails frameworkshttps://github.com/thesp0nge/dawnscannerFreecode_analysis
CodeCatAutomatic code static analysis tool to detect bugs and vulnerabilitieshttps://github.com/CoolerVoid/codecatFreecode_analysis
CodeQLSemantic code analysis engine; discover vulnerabilities across a codebase, lets you query code as though it were data, write a query to find all variants of a vulnerabilityhttps://github.com/github/codeqlFreecode_analysis
Kube-hunterScanner for security weaknesses in Kubernetes clustershttps://github.com/aquasecurity/kube-hunter/Freecode_analysis
AdhritAndroid APK reversing and analysis suitehttps://github.com/abhi-r3v0/AdhritFreecode_analysis
AndroBugs FrameworkAndroid APK vulnerability analyzerhttps://github.com/AndroBugs/AndroBugs_FrameworkFreecode_analysis
cIFrexRegexp static code analysishttps://github.com/MaksymilianA/cifrexFreecode_analysis
LICMALanguage Independent Crypto-Misuse Analysis; multi-language analysis tool to identify incorrect initialization of crypto functionshttps://github.com/stg-tud/licmaFreecode_analysis
MobSFAndroid APK vulnerability analyzerhttps://github.com/MobSF/Mobile-Security-Framework-MobSFFreecode_analysis
SemgrepStatic analysis engine for detecting vulnerabilities for many languageshttps://github.com/returntocorp/semgrepPaidcode_analysis
StaCoAnMobile applications static code analysis toolhttps://github.com/vincentcox/StaCoAnFreecode_analysis
SUPERAndroid APK vulnerability analyzerhttps://github.com/SUPERAndroidAnalyzer/superFreecode_analysis
NodeJsScanStatic security code scanner for Node.js applicationshttps://github.com/ajinabraham/NodeJsScanFreecode_analysis
SonarQubeAutomatic code review tool to detect bugs, vulnerabilities; continuous code inspection automated with static code analysis ruleshttps://github.com/SonarSource/sonarqubeFreecode_analysis
TrivyVulnerability and misconfiguration scanner for containers (OS and language-specific packages)https://github.com/aquasecurity/trivyFreecode_analysis
weggliSemantic search tool for C and C++ designed to help security researchers identify interesting functionality in large codebaseshttps://github.com/weggli-rs/weggliFreecode_analysis
TfsecMisconfiguration scanner for terraform codehttps://github.com/aquasecurity/tfsecFreecode_analysis
wpBulletStatic code analysis for WordPress Plugins and Themes (and PHP)https://github.com/webarx-security/wpbulletFreecode_analysis
QARKAndroid APK vulnerability analyzerhttps://github.com/linkedin/qarkFreecode_analysis