Whispers Logo

Whispers

0
Free
Visit Website

Whispers is a static code analysis tool designed for parsing various common data formats in search of hardcoded credentials and dangerous functions. Whispers can run in the CLI or you can integrate it in your CI/CD pipeline. It detects Passwords, API tokens, AWS keys, Private keys, Hashed credentials, Authentication tokens, Dangerous functions, and Sensitive files. Whispers supports formats like YAML, JSON, XML, .npmrc, .pypirc, .htpasswd, .properties, pip.conf, conf/ini, Dockerfile, Dockercfg, Shell scripts, Python3, JavaScript, Java, Go, PHP, AWS credentials files, JDBC connection strings, Jenkins config files, SpringFramework Beans config files, Java Properties files, Dockercfg private registry auth files, and Github tokens. Python3 files are parsed as ASTs because of native language support. Whispers is intended to be a structured text parser, not a code parser.

FEATURES

ALTERNATIVES

A tool that safely installs packages with npm/yarn by auditing them as part of your install process.

Automatic authorization enforcement detection extension for Burp Suite

A security-focused general purpose memory allocator providing the malloc API with hardening against heap corruption vulnerabilities.

Automatically redirect users from www to non-www for a secure connection.

IronBee is an open source project building a universal web application security sensor.

An application security platform that combines API discovery, multiple security testing methodologies, and continuous monitoring to protect modern applications throughout their development lifecycle.

A free online tool that scans and fixes common security issues in WordPress websites.

Black Duck is an application security platform that provides software composition analysis and supply chain security capabilities to identify vulnerabilities, ensure license compliance, and manage SBOMs throughout the software development lifecycle.