Code Analysis
XSS in PHP Source Code
SpotBugs
Java Code
Semgrep
Rules - C/C++
Rules - Python, Javascript/GraphQL, Go, Rust
Rules - Java/Android, PHP, Kotlin
Rules - Multiple Languages
Sonarqube
Scan
Snyk
Online
Not recommanded or remove sensitive information
Snyk CLI
CodeQL
Example with Visual Studio:
Vulnhuntr
PHP Static Analysis Tool
List of Static Application Security Testing (SAST) Tools
Resources
SEI CERT C Coding Standard
SEI CERT C++ Coding Standard
SEI CERT Oracle Coding Standard for Java
OWASP Secure Coding Practices
Last updated