Code Analysis

Static Code Analysis - Tools

ko-fi

Sourcebot

Training - Vulnerable Code Snippets

Search for credentials

Credentials in git repos

XSS in PHP Source Code

PHP Code Analysis

SpotBugs

Java Code

Semgrep

Rules - C/C++

Rules - Python, Javascript/GraphQL, Go, Rust

Rules - Java/Android, PHP, Kotlin

Rules - Multiple Languages

Opengrep

Sonarqube

Scan

Snyk

Online

Not recommanded or remove sensitive information

Snyk CLI

CodeQL

Example with Visual Studio:

Vulnhuntr

PHP Static Analysis Tool

Dependency Takeover - Node.js

List of Static Application Security Testing (SAST) Tools

Resources

SEI CERT C Coding Standard

SEI CERT C++ Coding Standard

SEI CERT Oracle Coding Standard for Java

OWASP Secure Coding Practices

Interesting Books

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Support this Gitbook

I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.

ko-fi

buymeacoffee

Last updated