finds.dev← search

// the find

swisskyrepo/Vulny-Code-Static-Analysis

★ 426 · PHP · NOASSERTION · updated Feb 2025

Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex

A regex-based CLI that scans PHP source for common vulnerability patterns (SQLi, XSS, LFI/RFI, SSRF, XXE, deserialization, weak crypto, etc.) and flags matching lines with file/line context. The author has explicitly deprecated it in favor of running the bundled semgrep rules against the same code, so it's really only useful today as the semgrep rules' origin repo and test corpus.

Covers a genuinely wide range of vulnerability classes (20+) in one pass with zero setup beyond Python. The semgrep/ directory has well-scoped, framework-aware rules (Laravel SQLi, Symfony CSRF/CORS, Doctrine DBAL) that are meaningfully more precise than the regex engine they replaced. The vulns/ folder is a clean one-file-per-vuln-class fixture set, handy as a quick smoke-test corpus for any PHP SAST tool, not just this one.

The maintainer tells you outright not to use the core tool and to run semgrep instead - the README leads with a deprecation warning. Regex matching on PHP has no concept of data flow, so it can't follow tainted input through variable reassignment, concatenation, or helper functions, which means both missed detections and noisy false positives on anything beyond the toy examples in vulns/. There's no test suite validating detection.py/functions.py logic, only static example files, and no versioned releases since the 1.0.0 beta tag, so the Python side is effectively frozen while GitHub's vuln landscape (e.g., modern Laravel/Symfony patterns) moves on.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →