Static analysis of Python web applications based on theoretical foundations (Control flow graphs, fixed point, dataflow analysis) Detect command injection, SSRF, SQL injection, XSS, directory traveral etc. A lot of customization is possible. For functions from builtins or libraries, e.g. url_for or os.path.join, use the -m option to specify whether or not they return tainted values given tainted inputs, by default this file is used.
Features
- Virtual env setup guide
- Detect command injection, SSRF, SQL injection, XSS, directory traveral etc.
- A lot of customization possible
- A Static Analysis Tool for Detecting Security Vulnerabilities
- Detect vulnerabilities in Python Web Applications
- Static analysis of Python web applications based on theoretical foundations
License
GNU General Public License version 3.0 (GPLv3)Follow Python Taint
Other Useful Business Software
Zenflow- The AI Workflow Engine for Software Devs
Zenflow is the AI workflow engine built for real teams. Parallel agents plan, code, test, and verify in one workflow. With spec-driven development and deep context, Zenflow turns requirements into production-ready output so teams ship faster and stay in flow.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of Python Taint!