Source Code Security Analysis (SAST)

SAST (Static Application Security Testing, WhiteBox Testing) solution for performing extensive security audits of application source code. Our solution is easy to use, requires almost no user input and can be deployed during or after development. It is an efficient alternative to the demanding and time-consuming manual code reviews. Our solution will perform fast and accurate analyses of large and complex source code projects delivering precise results and low false positive rate.

We scans for more than 30 vulnerability types (including OWASP Top 10) in desktop, web and mobile applications developed on various platforms using different development environments and frameworks. Some of these are listed below:

  • SQL Injection
  • XPATH Injection
  • File Disclosure
  • Mail Relay
  • Page Inclusion
  • Dangerous Configuration Settings
  • Code Injection
  • Dangerous File Extensions
  • Shell Command Execution
  • Misc. Dangerous Functions
  • Cross Site Scripting
  • Arbitrary Server Connection
  • Weak Encryption
  • HTTP Response Splitting
  • Information Leaks
  • LDAP Injection

Application source code analysis is the best and most comprehensive way to assure your application is free of security vulnerabilities (SQL Injections, Cross Site Scripting Vulnerabilities, File Inclusion, Code Execution, etc.).

Our solution is designed to perform comprehensive security assessment of desktop, web and mobile application source code and it has repeatedly proven its effectiveness by discovering critical vulnerabilities in popular open source applications.