nowfound

Alternatives

Products that do what Ansede. Live Security Scanner Playground does

100% Offline SAST, Finds What Semgrep & CodeQL Miss

  1. 1

    Secure code in less than 5 minutes for free

    2022

  2. 2

    AI powered code security analysis

    2023

  3. 3
    RustScan108

    Fast and developer-friendly Rust contract security scanner

    2025

  4. 4
    Probely87

    Intuitive and easy-to-use webapp vulnerability scanner

    2018

  5. 5SA

    https://semgrep.dev/products/semgrep-app Hi! I work on Semgrep, an open-source project (discussed on HN previously [0][1)]. We’re one of those companies that maintain an OSS tool and a web app, and then monetize by selling enterprise features on said web app. Our free web app just went through a major revamp (sort of like a v1.0 release) so this feels like the perfect time to share and hear what the HN crowd thinks! Let me start with some backstory on Semgrep. Our team, r2c, has been experimenting with various ways to help organizations step up their application security…

    2021

  6. 6

    Observer — scan your code for security issues, 100% offline

    10d ago · github.com

  7. 7IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  8. 8TS

    Hi HN, I’m Guillaume, the cofounder of Bearer, an Open Source SAST solution. After launching a few weeks ago here on Hacker News with support for Ruby and JavaScript stacks, I’m happy to report we’ve just released a new version (v1.2) with TypeScript support! In terms of code coverage, we use the same rules already implemented for vanilla JavaScript, but as usual, you can build your own. The rules list is here: https://docs.bearer.com/reference/rules/ It’s a first version for TS, but we believe that thanks to the pre-existing JavaScript support it should already…

    2023

  9. 9BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com

  10. 10ST
  11. 11TO

    I'm an infrastructure architect who started using AI assistants to write code 3 months ago. After building several systems with Claude, I noticed a pattern: the code always had security issues I could spot from my ops background, but I couldn't fix them myself since I can't actually write code. Why I built this: I needed a way to verify AI-generated code was production-safe. Existing tools either required cloud uploads (privacy concern) or produced output too large for AI context windows. TheAuditor solves both problems - it runs completely offline and chunks findings into 65KB segments that…

    Sep 2025 · github.com

  12. 12

    Find outdated deps and CVEs across 8 ecosystems in VS Code

    Jun 2026 · scanreq.com

  13. 13

    Modern Python source code security analyzer.

    Jul 2026 · nocomplexity.com

  14. 14SO

    We're open-sourcing Sighthound today, our rules-based static security scanner. What makes it special is that it's coded in rust and uses tree-sitter as it's AST making it very fast and easily extensible. Why build another scanner in 2026? We wanted to improve some of our detection outcomes but noticed the current open source scanners like Semgrep/Opengrep we're capped by a bunch of adoption limitations such as being written in OCaml, requiring a lot of work to add a language parser, and the rulesets were licensed differently and required paid offerings. It also felt that licensing was…

    Jul 2026 · github.com

  15. 15

    Free security scan that tells you exactly how to fix it

    Jun 2026

  16. 16MA
  17. 17

    Passive blue-team security scanner — 582 read-only modules, plus 32 opt-in probes. Runs on your machine. No accounts. No telemetry. - taylannuhogluofficial-png/Tblue

    13d ago · github.com

  18. 18WS

    http://webscanner.tk/quickscan/ Hi! I made this project over the couse of a week to help teach myself more about Django and web app development. I am studying computer security in school and web security is one of my passions. It is a tool that helps web developers ensure that they have implemented helpful security mechanisms like HTTPOnly flags, X-Frame-Options, etc. There are hundreds of tools that offer to scan websites for things like cross-site scripting, mySQL injection, etc. This tool simply looks for information that is available via one or two GET requests (the headers, protocols,…

    2013

  19. 19

    An automated security check for apps built with Bolt, Cursor or v0. Plain-English findings and a copy-paste fix. No jargon, no terminal.

    17d ago · sentrint.com

  20. 20

    You vibe-code fast. We keep it secure.

    Apr 2026 · codesafe.co.in

  21. 21

    AI that spots real risks and keeps your code safe.

    Dec 2025

  22. 22AS
  23. 23

    Catch code vulnerabilities before they ship.

    Jul 2026 · vuln-shield.vercel.app

  24. 24

    World's Largest Exploit Database

    27d ago · exploit.observer

Ranked by how close each launch is in meaning, then by votes. Refine with a description →