Semgrep

Analyser that reads your code at rest and flags dangerous patterns: hardcoded secret, concatenated query, unvalidated input. What sets it apart is its rules, written to look like the code they hunt, with wildcards, rather than as a regular expression or a syntax tree walk. Thirty-plus languages, open source engine, ready-made community rules.

Strengths

Limitations

Best for

Official site

View on Coeurdar