SCodeScanner – Stands For Source Code Scanner Where The User Can Scans The Source Code For Finding The Critical Vulnerabilities
SCodeScanner stands for Source Code scanner where the user can scans the source code for finding the Critical Vulnerabilities. The main objective for this scanner is to find the vulnerabilities inside the source code before code gets published in Prod.
Features
- Supported PHP Language
- Supported YAML Language
- Pass results to bug tracking services like Jira also Slack (Sending files to group to multiple people at once).
- Gives results in JSON format, which can easily be used to any other program.
- Works with Rules. We only need to create some rules which the target rule is not present in php/yaml directory.
- Rules that can scan advance patterns
Achievements
SCodeScanner received 5 CVEs for finding vulnerabilities in multiple CMS plugins.
- CVE-2022-1465
- CVE-2022-1474
- CVE-2022-1527
- CVE-2022-1532
- CVE-2022-1604
How to run?
- Download the repository –
- Run
pip3 install -r requirements.txt
- And run
python3 scscanner.py --help
Feedback/Imporvements
I would love to hear your feedback on this tool. Open issues if you found any. And open PR request if you have something.
Contact
Utkarsh Agrawal
Website
Download Scodescanner
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.