Source Code Auditing
Source Code Auditing
.NET Security Guard - Roslyn analyzers that aim to help security audits on .NET
applications. It will find SQL injections, LDAP injections, XXE, cryptography
weakness, XSS and more.
RIPS - RIPS Open Source is a static source code analyzer for vulnerabilities in PHP
web applications.
VisualCodeGrepper (VCG) - Scans C/C++, C#, VB, PHP, Java, and PL/SQL for
security issues and for comments which may indicate defective code.
YASKA - YASCA (Yet Another Source Code Analyzer) analyzes Java, and C/C++
primarily, with other languages and JavaScript for security flaws and other bugs.
CHECKMARKS TOOL
SONAR CUBE