Bandit
PyCQA
An AST-based security linter for Python that flags common insecure patterns such as unsafe deserialization, shell injection and weak crypto.
SAST
Analyze source code or bytecode for vulnerable patterns without running the application.
31 tools profiled
How it differs Reads the code you wrote without running it. SCA checks the third party packages you depend on; IAST watches the running app while your tests exercise it.
PyCQA
An AST-based security linter for Python that flags common insecure patterns such as unsafe deserialization, shell injection and weak crypto.
Go Security (securego)
A Go security scanner that inspects the AST and SSA representation to flag unsafe patterns such as command injection, weak crypto and unhandled errors.
OpenText
A long-established enterprise static analyzer with very broad language support, rule-driven taint analysis and detailed compliance reporting.
PyCQA
An AST-based security linter for Python that flags common insecure patterns such as unsafe deserialization, shell injection and weak crypto.
Go Security (securego)
A Go security scanner that inspects the AST and SSA representation to flag unsafe patterns such as command injection, weak crypto and unhandled errors.
OpenText
A long-established enterprise static analyzer with very broad language support, rule-driven taint analysis and detailed compliance reporting.
PMD open source project
Extensible source code analyzer that applies rule sets to the syntax tree of several languages, bundled with a cross language copy and paste detector.
Sonar
IDE extension that analyzes code as you type and, in connected mode, applies the same rules and suppressions as your server side Sonar analysis.
SpotBugs project
Successor to FindBugs that analyzes compiled JVM bytecode against a catalog of bug patterns, extensible with security focused detector plugins.
PMD open source project
Extensible source code analyzer that applies rule sets to the syntax tree of several languages, bundled with a cross language copy and paste detector.
Sonar
IDE extension that analyzes code as you type and, in connected mode, applies the same rules and suppressions as your server side Sonar analysis.
SpotBugs project
Successor to FindBugs that analyzes compiled JVM bytecode against a catalog of bug patterns, extensible with security focused detector plugins.