Salesforce Code Analyzer is a unified tool to help Salesforce developers analyze their source code for security vulnerabilities, performance issues, best practices, and more.
UI Client for Unlighthouse.
Find broken links, missing images, etc in your HTML. Scurry around your site and find all those broken links.
Theia - SCANOSS AI Integration
Abstraction for DynamoDB queries and scans that handles pagination and parallel worker coordination
MCP server that scans other MCP servers for prompt injection, data exfiltration, and privilege escalation. Add to your .mcp.json and let your AI agent audit its own tools.
Components scan utilities for Ts.ED Framework
CLI that fails if any package version in (or newly added to) a lockfile is younger than a configurable threshold on the npm registry. Defends against supply-chain attacks via a quarantine window.
Security Trust Report: @cairncms/api@1.0.0 — 58/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.
Implementation of the Graham Scan algorithm to calculate a convex hull from a given array of x, y coordinates.
Audits NPM, Yarn, and PNPM projects in CI environments
MCP security trust layer. Scan packages, inspect repo MCP dependencies, generate Policy Gate setup, check exposure, and query abuse data.
The MDN HTTP Observatory is a set of tools to analyze your website and inform you if you are utilizing the many available methods to secure it.
Theia - SCANOSS Integration
This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us the rights to use your contribution. For details, visit
Supply-chain scanner: lockfile checks, code detectors, cache scans.
A plugin to scan a file for a string or expression
Static code scanner that applies quality and security rules to Apex code, and provides feedback.
Consumer-scan parser for React JSX. Detects component usages in .tsx and .jsx files.
Consumer-scan parser for Vue Single-File Components. Detects component usages in .vue files.
AWS CDK security and cost analysis CLI. Free static scans via npm — no account needed. Sign up free to add AI-powered insights.
Consumer-scan parser for Lit `html\`\`` tagged template literals inside .ts and .js files.
Gamified local security CLI for hunting common code vulnerabilities from npm.
Convert axe-core accessibility scan results to the SARIF format