oxsecurity / codetotalLinks
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
☆78Updated 11 months ago
Alternatives and similar repositories for codetotal
Users that are interested in codetotal are comparing it to the libraries listed below
Sorting:
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.☆56Updated 2 months ago
- ☆112Updated 2 years ago
- Dependency Combobulator☆93Updated last year
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆23Updated 3 years ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆105Updated 6 months ago
- 🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends☆73Updated last year
- Manager of third-party sources of Semgrep rules 🗂☆87Updated last year
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆119Updated last year
- ☆72Updated last week
- Scan DockerHub images that match a keyword to find secrets.☆60Updated 4 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆49Updated 2 years ago
- ☆58Updated 2 years ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆42Updated last year
- 🔍A cutting edge context aware GraphQL API fuzzing tool!☆143Updated 2 weeks ago
- Secrets scanner that understands code☆188Updated last year
- ☆17Updated 3 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Updated 3 years ago
- boostsecurityio/lotp☆131Updated 3 months ago
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆27Updated 4 months ago
- WAF bypass PoC☆48Updated last year
- GCP GOAT is the vulnerable application for learn the GCP Security☆64Updated 2 months ago
- ☆116Updated 2 years ago
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆134Updated 4 months ago
- A curated list of argument injection vectors☆41Updated 6 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆40Updated 7 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆42Updated last week
- Burp Suite extension for testing Passkey systems.☆73Updated 4 months ago
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes☆43Updated last year
- ☆140Updated last week
- Nuclei plugins to audit Chrome extensions☆65Updated last year