JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
-
Updated
Sep 14, 2026 - TypeScript
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
A tool for mining commits from Git repositories and diffs to automatically extract code change pattern instances and features with ast analysis
Stop shipping AI slop. Detects empty functions, fake documentation, and inflated comments in AI-generated code. Production-ready.
Multi-language static analysis with cross-file taint tracking. Scan your repo, triage findings in your browser, commit triage state with your code. No cloud, no account.
LibSA4Py: Light-weight static analysis for extracting type hints and features
Auto-derives codebase conventions from repo analysis and injects archetype-aware guidance into AI-generated code, enforcing team idioms, banned imports, and framework-specific patterns for TypeScript/JavaScript, Ruby, and Python projects.
⚡ JavaScript-aware crawler for security researchers and bug bounty hunters. Extract hidden endpoints and internal subdomains through static and semantic analysis of JS files. Lightweight. Fast. Sneaky.
Whole-program callgraph reachability pruner locating dead functions & stale flags (Knip / Tsukuyomi)
Static AST dataflow tracer following untrusted sources to sensitive sinks (Semgrep / Snyk)
Static AST dataflow tracer following untrusted sources to sensitive sinks (Semgrep / Snyk)
Whole-program callgraph reachability pruner locating dead functions & stale flags (Knip / Tsukuyomi)
Asynchronous control flow auditor identifying unawaited promises & race conditions (ESLint)
Git PR diff semantic analyzer detecting breaking REST/GraphQL API schema mutations (Optic / Buf)
Git PR diff semantic analyzer detecting breaking REST/GraphQL API schema mutations (Optic / Buf)
Automated test suite trace analyzer identifying timing races & state pollution (Datadog CI / Trunk)
Automated test suite trace analyzer identifying timing races & state pollution (Datadog CI / Trunk)
Asynchronous control flow auditor identifying unawaited promises & race conditions (ESLint)
Formal adversarial testing of LLM-generated industrial robot (URScript) code: ISO 10218-1:2025 safety + CWE security analysis, AST static watchdog, URSim runtime. Simulation-only.
🔍 Automatically detect duplicate logic in Python code changes. Prevent code duplication and improve code quality.
Revolutionary AST-based debugging and code intelligence platform for Elixir applications
To associate your repository with the ast-analysis topic, visit your repo's landing page and select "manage topics."