GraphQL-specific security scanner. Detects introspection exposure, field harvesting, depth/complexity attacks, batch abuse, and injection.
-
Updated
Mar 16, 2026 - Go
GraphQL-specific security scanner. Detects introspection exposure, field harvesting, depth/complexity attacks, batch abuse, and injection.
[MIRROR] self-hosted WAF to protect your websites from attacks and exploits
Yet another simple WAF build with golang
Advanced SBOM visualization tool. Provides graphical information about the dependency stack of your application, list of vulnerabilities and overall application health. Supports multiple methods of data aggregation and filtering in a convenient, modern interface.
Text Janitor is a a comprehensive text analysis and cleaning toolkit developed by Martin Mkrtchian for maintaining code quality and text hygiene across your projects.
A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
Secrets & hash scanner written in Go (API keys, tokens, high-entropy strings, hash types & crackability hints).
Risk-based compliance mapper and release gate for SOC 2, NIS 2 e DORA. Context over thresholds.
Secret Scanner
A terminal interactive game designed to train yourself to identify insecure coding practices.
Passive recon golang module to expand testing targets (subdomains and urls)
urlyzer is a URL parsing analysis tool.
Static secret scanner for CI/CD pipelines. Entropy-based false positive reduction. Zero external dependencies. Built for environments where network-verified tools cannot run.
Multitool for Enhancing Code Security
Ghosted is a Trust Erosion scanner, pulling domains from your CSP checking if they're available to buy.
Interaction-based application security / quality tool (Control Unit)
Add a description, image, and links to the appsec topic page so that developers can more easily learn about it.
To associate your repository with the appsec topic, visit your repo's landing page and select "manage topics."