Detects cases of trojan source attacks that employ unicode bidi attacks to inject malicious code. If you're using ESLint, see eslint-plugin-anti-trojan-source for a purpose-built plugin to detect anti-trojan characters. This tool is important in identifying potential supply chain attacks where adversaries can inject malicious code into the source code of a project, slipping by unseen in the code review process.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
WordPress plugin to reduce comment spam with a smarter honeypot.
An API security platform that provides automated security testing, runtime protection, and lifecycle management for APIs through integrated tools and controls.
An IDE-integrated AI security solution that detects, remediates, and educates about code vulnerabilities in real-time as developers write code.
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.
A set of 48 practical programming exercises in cryptography and application security
Application monitoring and security platform that provides runtime visibility, threat detection, and automated response capabilities for application-layer security
Hack with JavaScript XSS'OR tool for encoding/decoding and various XSS related functionalities.
An integrated application security platform that combines multiple security scanning tools with developer-focused workflows for automated code and infrastructure security testing.
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.