Static Application Security Testing

Static Application Security Testing (SAST) tools for static code analysis that detect security vulnerabilities and coding flaws in source code during development.

Explore 74 curated cybersecurity tools, with 14,802+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

detect-secrets Logo

A pre-commit security tool that scans source code repositories to detect and prevent secrets like API keys, passwords, and credentials from being committed to version control systems.

0
Talisman Logo

Pre-commit hook for validating outgoing changeset

0
DOMXSS Scanner Logo

A free online tool to scan for DOM-based XSS vulnerabilities in HTML, JavaScript, and CSS files.

0
Insider Logo

Insider is an open-source CLI tool that performs static source code analysis to detect OWASP Top 10 vulnerabilities across multiple programming languages including Java, Kotlin, Swift, .NET, C#, and JavaScript.

0
EarlyBird Logo

A sensitive data detection tool for scanning source code repositories

0
StaCoAn Logo

StaCoAn is a cross-platform tool for static code analysis on mobile applications, emphasizing the identification of security vulnerabilities.

0
SearchCode Logo

SearchCode is an extensive code search engine that indexes 75 billion lines of code from millions of projects to help developers find coding examples and libraries.

0
Betterscan Logo

Betterscan is an orchestration toolchain that coordinates multiple security tools to scan source code and infrastructure as code for security vulnerabilities, compliance risks, secrets, and misconfigurations.

0
Bearer CLI Logo

Bearer CLI is a static application security testing tool that scans source code across multiple programming languages to identify and prioritize OWASP Top 10 and CWE Top 25 security vulnerabilities through data flow analysis.

0
Strong Node.js Logo

Exhaustive checklist for securing Node.js web services with a focus on error handling and custom error pages.

0
@hapi/bourne Logo

JSON.parse() drop-in replacement with prototype poisoning protection.

0
Entropy Source Evaluation Logo

Using high-quality entropy sources for CSPRNG seeding is crucial for security.

0
Envalid Logo

A Node.js library for validating environment variables and providing immutable access to configuration values in applications.

0
Rusty Hog Logo

A suite of secret scanners built in Rust for performance.

0
Tracy Logo

A tool for identifying potential security vulnerabilities in web applications

0
Dependencies Logo

Dependencies is an open-source modern replacement for Dependency Walker that helps Windows developers analyze and troubleshoot DLL load dependency issues.

0
Securibench Micro Logo

A collection of vulnerable web application test cases designed to benchmark and evaluate the effectiveness of static security analyzers and penetration testing tools.

0
Quick Android Review Kit Logo

QARK is a static analysis tool that scans Android applications for security vulnerabilities and can generate proof-of-concept exploits for discovered issues.

0
DroidRA Logo

DroidRA is an instrumentation-based Android security analysis tool that improves the accuracy of reflective call analysis through composite constant propagation techniques.

0
validator.js Logo

A library of string validators and sanitizers.

0
SecretScanner Logo

SecretScanner is a standalone tool that scans container images and filesystems to detect approximately 140 types of unprotected secrets and sensitive credentials.

0
git-secrets Logo

Prevents you from committing passwords and other sensitive information to a git repository.

0
UglifyJS 3 Logo

UglifyJS 3 is a JavaScript toolkit that provides parsing, minification, compression, and beautification capabilities for JavaScript code optimization and processing.

0
Nuxt Security Logo

A Nuxt 3 security module that automatically implements OWASP security patterns through HTTP headers, middleware, and various protection mechanisms including CSP, XSS validation, CORS, and CSRF protection.

0