Skip to main content

Logo

Static-Code-Analysis-Helper Version License Python Version Docker

Static-Code-Analysis-Helper

Description

It detects functions that are likely to cause attack methodologies in many web programming languages ​​and frameworks in your project folder.

Helps you perform static code analysis.

Note : Many of the functions described here may not cause vulnerabilities.

ScreenShot

Programming Languages

  • Go
  • Python
  • Ruby
  • PHP
  • JavaScript
  • Java
  • Rust
  • Perl
  • Ruby on Rails
  • Swift
  • Golang
  • Scala
  • Kotlin
  • Julia
  • Dart
  • ASP.NET Core

Types of attacks related to results

SQLi, XSS, XXE, CSRF, SSTI, SSRF, IDOR, CORS, XSHM, LFI, DoS, DDoS, RFI, Weak Encryption / Insecure Cryptographic Storage, Path Traversel, Session Attacks,Open Redirect, Insecure File Permissions, XPath Injection, File Uploads, Memory Corruption / Buffer Overflow, Security Misconfiguration, Reflected File Download, CSV Injection, Command Injection, WebSocket Vulnerabilities, Race Condition, Code Injection, Malicious File Deserialization, JWT Vulnerabilities, Broken Access Control, Content Spoofing, Authentication Vulnerabilities, Cookie Vulnerabilities, Business Logic Vulnerabilities.

TODO

  • ******** Private Repository
  • ******** Private Repository
  • Scan Multiple Programming Language with MultiThread
  • Detecting functions that contain other structures. Environment variables etc.
  • Feature to download from Github, Gitlab or Bitbucket to the repository periodically.

NOTE : Please See; USAGE_POLICY.md LICENSE

Installation

From Git


git clone https://github.com/OsmanKandemir/static-code-analysis-helper.git
cd static-code-analysis-helper
python3 scanner.py -f "/Users/Test/ProjectFolder" -o result.txt

From Source Code

git clone https://github.com/OsmanKandemir/static-code-analysis-helper.git
cd static-code-analysis-helper
python -m build
python setup.py install

From Pypi

Function Usage

from StaticCodeAnalysisHelper import FileScan

# Specific Programming Language Scan

FileScan.AdvancedFileScanning("/Desktop/My-Project","java","result.txt")

# Full Scan

FileScan.AdvancedFileScanning("/Desktop/My-Project",None,"result.txt")

From Dockerfile

docker build -t staticcodeanalysishelper .
docker run -v <YOUR-PROJECT-PATH-FOLDER>:/static-code-analysis-helper/Project staticcodeanalysishelper -f /static-code-analysis-helper/Project -p <YOUR-PROGRAMMING-LANGUAGE>

From DockerHub

Usage


-f FOLDER [FOLDER], --folder Folder [FOLDER] Project Folder Path. --folder
-p PROGRAMMING [PROGRAMMING], --programming python [PROGRAMMING] Select Programming Language. --programming
-o OUTPUT [FILENAME] --output [FILENAME] Save output. --output

Programming Language List : java, asp.net, python, dart, ruby, go, php, rust, javascript, perl, scala, golang, kotlin, julia

Please, scan the only project files for the correct result.

Development and Contribution

To continue developing the application StaticCodeAnalysisHelper/LanguagesFunctions.py you can add new functions to the file according to the following syntaxes.

{"function": "function()","description": "description"}
{"function": "function[]","description": "description"}
{"function": "function","description": "description"}

See; CONTRIBUTING.md

License

Copyright (c) 2025 Osman Kandemir
Licensed under the GPL-3.0 License.

Donations

If you like Static-Code-Analysis-Helper and would like to show support, you can use Buy A Coffee or Github Sponsors feature for the developer using the button below.

Or

Sponsor me : https://github.com/sponsors/OsmanKandemir 😊

Buy Me A Coffee

Your support will be much appreciated😊

Metadata

Release files for StaticCodeAnalysisHelper 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for StaticCodeAnalysisHelper 1.0.0
File Size Uploaded
staticcodeanalysishelper-1.0.0.tar.gz 28.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for StaticCodeAnalysisHelper 1.0.0
File Interpreter ABI Platform
staticcodeanalysishelper-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 55.7 kB

Release files / staticcodeanalysishelper-1.0.0.tar.gz

Download URL staticcodeanalysishelper-1.0.0.tar.gz
Size 28.5 kB
Tags Source
SHA-256 checksum
How to use checksums
317c58ea111622d6993b5d0d2c7f1cbf63ad859297e0d1c144ff6caa518d62e3
BLAKE2b-256 checksum
How to use checksums
3518bf1f5fd21fcc4a603ff02002b2427896543ca5d93196bf8dbd67201a0c93
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.2

Release files / staticcodeanalysishelper-1.0.0-py3-none-any.whl

Download URL staticcodeanalysishelper-1.0.0-py3-none-any.whl
Size 27.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
04d1ef0d8749266ec258399ae8bd025ce032cca9703b1796d5692e6dec03a1bf
BLAKE2b-256 checksum
How to use checksums
b835d8a5d7f6cab7e8c0df0762c1b37d2a26c6a13358839c0247048fe7686035
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.2

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page