Only 42 of 755 Static-Analysis Tools Are Open-Source Security Scanners
An analysis of the public analysis-tools.dev catalog, which lists 755 static-analysis tools under an MIT license, found that while 86% of all tools are open source, only 42 qualify as both open-source and security-focused. Security scanners differ from general linters in that they trace potentially dangerous data flows, such as unparameterized SQL inputs, rather than flagging style or complexity issues. The gap is most striking at the language level: 21 languages that already have five or more general static-analysis tools, including Shell, SQL, PowerShell, and Dart, have no open-source security scanner at all. Security tooling is heavily concentrated in Python, Go, Java, and JavaScript, which each have between 9 and 13 dedicated scanners. The findings are drawn from a single publicly available dataset and the authors have published their parser and raw counts so the results can be independently verified.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in