pauljt / scanjs
Static analysis tool for javascript code based. Scanjs uses Esprima to convert sources to AST, then walks AST looking for patterns.
☆54Updated 10 years ago
Alternatives and similar repositories for scanjs:
Users that are interested in scanjs are comparing it to the libraries listed below
- A dashboard for interesting DOM tricks/techniques.☆36Updated 4 years ago
- rules for scanjs functionality☆28Updated 3 years ago
- [DEPRECATED] Static analysis tool for javascript code.☆428Updated 3 years ago
- Popcorn - the JSON fuzzer☆22Updated 10 years ago
- SSRF Protection Library for PHP - http://safecurl.fin1te.net☆73Updated last year
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 3 years ago
- Discussion area for security aspects of ECMAScript☆64Updated 7 years ago
- JavaScript Static Code Analysis☆24Updated 10 years ago
- Grunt plugin for retire.☆88Updated last year
- JavaScript parser and sandbox☆79Updated 8 years ago
- A deliberately vulnerable modern day app with lots of DOM related bugs☆36Updated 5 years ago
- jPurify☆66Updated 8 years ago
- Use burp's JS static code analysis on code from your local system.☆42Updated 8 years ago
- Immunio's XSS Fuzzer tool☆25Updated 9 years ago
- ☆74Updated 12 years ago
- This is a tiny Chrome Extension that protects your from Clipboard XSS Attacks☆19Updated 10 years ago
- Tainted PhantomJS☆53Updated 9 years ago
- JITed Taint Tracking in V8☆15Updated 10 years ago
- My blog where I make a new coding project every Thursday.☆44Updated last year
- Surku is a general-purpose mutation-based fuzzer.☆79Updated 2 years ago
- A library to assist in security-testing Unicode enabled applications during fuzzing, XSS, SQLi, etc.☆42Updated 7 years ago
- A visual fuzzer written in NodeJS to find Zalgo characters☆53Updated 7 years ago
- An example of obtaining RCE via Redis and CSRF☆76Updated 8 years ago
- ReDoS - test for regular expression DoS in JavaScript☆25Updated 3 years ago
- Reflective/DOM XSS scanner built on casperJS☆81Updated 10 years ago
- frida utility-belt☆24Updated 8 years ago
- Exposing and documenting v8 runtime functions.☆28Updated 10 years ago
- An ultra-compact intro (or refresher) to Web Application Security.☆31Updated 7 years ago
- Checks filenames to be committed against a library of filename rules to prevent sensitive files in Git☆66Updated last week
- The databases, API's and managers behind https://websecweekly.org☆50Updated 10 years ago