GitHub repo leaderboard by stars, growth rate and activity.
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
DianXing - AI-Driven End-to-End Code Security Auditing
OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws while minimizing both false positives and false negatives. Stage 1 detects. Stage 2 attacks. What survives is real.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | ⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality. | Rust | 14,773 | last pushed 2 days ago | |
| 2 | Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure. | Go | 5,212 | last pushed 10 months ago | |
| 3 | Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc... | TypeScript | 2,081 | last pushed 3 days ago | |
| 4 | Find leaked secrets everywhere. | Go | 1,891 | last pushed Yesterday | |
| 5 | APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code. | Go | 974 | last pushed 2 years ago | |
| 6 | DianXing - AI-Driven End-to-End Code Security Auditing | — | 873 | last pushed 3 months ago | |
| 7 | OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws while minimizing both false positives and false negatives. Stage 1 detects. Stage 2 attacks. What survives is real. | Python | 747 | last pushed Yesterday |
All · 11,474