Semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Filament plugins, Laravel packages and open source starter kits actively maintained. All MIT, with releases for v3, v4 and v5 where applicable.
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
Laravel-aware security rules for php-security-scanner. Detects Laravel SQL injection (DB::raw, whereRaw), mass assignment, debug/dd leaks, unsafe validators, CSRF bypass, insecure cookies, env exposure, Blade raw echo, open redirect, Http SSRF, Storage/File path traversal, file-upload validation gaps, Auth/Crypt/Artisan/Process/Config injection, view-name injection, session fixation, and Mail header injection.
Framework-agnostic static security scanner for PHP. Detects SQLi, XSS, command injection, path traversal, insecure deserialization, weak crypto, hardcoded secrets, and more.
All packages have CI, Pest tests and open issues tagged good first issue.
New version available.