190 tools across 17 categories. Filter by what you actually need — your language, your budget shape, whether it has to run on your own infrastructure.
23 tools
Security Testing
The professional web security tester's tool of choice, plus an enterprise scanner.
Security Testing
Free dependency updates and vulnerability alerts, built into GitHub.
Security Testing
The free, open-source DAST scanner that attacks your running application.
Security Testing
Highly configurable automated dependency updates, free and self-hostable.
Code Quality
Extremely fast Python linter and formatter that replaces most of the toolchain.
Security Testing
Developer-first security across dependencies, code, containers and infrastructure.
Code Quality
The static-analysis standard: 30+ languages, quality gates, clean-as-you-code.
Security Testing
One open-source scanner for containers, filesystems, repos, IaC and Kubernetes.
Security Testing
Enterprise application security platform: SAST, SCA, DAST, IaC and API security.
Security Testing
Query your codebase like a database to find vulnerability patterns across the whole repo.
Security Testing
Secrets detection across your repositories, history and developer machines.
Security Testing
Software composition analysis with automated remediation and licence compliance.
Security Testing
Pattern-based static analysis where rules look like the code they match.
API Testing
The long-standing tool for SOAP, JMS and enterprise protocol testing.
Security Testing
Open-source secret scanning that verifies whether the credential is still live.
Security Testing
Application security as a service, with policy enforcement and compliance attestation.
Code Quality
Automated code review with security scanning and coverage in the pull request.
Code Quality
Static analysis with autofix, tuned hard for low false-positive rates.
Security Testing
DAST with proof-based scanning that confirms a vulnerability is real before reporting it.
Code Quality
JetBrains' IDE inspections, running as a CI quality gate.
API Testing
Property-based fuzzing that generates API tests straight from your OpenAPI schema.
Test Data & Mocks
De-identify production data into safe, realistic, referentially intact test databases.
Test Data & Mocks
Open-source data anonymisation and synthetic-data generation you can self-host.
Filters