sast
Tracked open-source repos tagged sast, sorted by stars.
Related topics
Topics that frequently appear alongside sast on the same repo.
Recent risers
Repos created in the last 90 days, tagged sast.
- #1
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
★ 16,483+45Star change over the last 7 days - #2
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
★ 14,760+6Star change over the last 7 days - #3
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
★ 6,937+18Star change over the last 7 days - #4
Plugin for JADX to integrate MCP server
★ 2,744+19Star change over the last 7 days - #5
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
★ 2,740+1Star change over the last 7 days - #6
nodejsscan is a static security code scanner for Node.js applications.
★ 2,574+2Star change over the last 7 days - #7
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
★ 2,062+7Star change over the last 7 days - #8
Find leaked secrets everywhere.
★ 1,828+18Star change over the last 7 days - #9★ 1,481+3Star change over the last 7 days
- #10
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
★ 1,333+0Star change over the last 7 days - #11
Collection of agent skills to find vulnerabilities inside your web/mobile apps.
★ 1,295+4Star change over the last 7 days - #12
AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an always-on AI attack-signature scanner and native Rust & PHP rules. Also: medusa scan --git to vet any repo, medusa secrets scan for leaked API keys. 40,000+ patterns, zero setup.
★ 976+5Star change over the last 7 days - #13
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
★ 974-2Star change over the last 7 days - #14
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
★ 946+165Star change over the last 7 days - #15
JavaSecLab is a comprehensive Java vulnerability platform| JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……
★ 876+1Star change over the last 7 days - #16★ 872+1Star change over the last 7 days
- #17
mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.
★ 783+2Star change over the last 7 days - #18
OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws while minimizing both false positives and false negatives. Stage 1 detects. Stage 2 attacks. What survives is real.
★ 746+9Star change over the last 7 days - #19
ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.
★ 691+4Star change over the last 7 days - #20
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
★ 670+102Star change over the last 7 days