VisualCodeGrepper V2.1.0 Icon

VisualCodeGrepper V2.1.0

Code security review tool for C/C++, C#, VB, PHP, Java and PL/SQL.

4.5 Stars (4)
198 Downloads (This Week)
Last Update:
Download VCG-Setup.zip
Browse All Files
Windows

Screenshots

Description

VCG is an automated code security review tool for C++, C#, VB, PHP, Java and PL/SQL which is intended to drastically speed up the code review process by identifying bad/insecure code.

It has a few features that should make it useful. In addition to performing some more complex checks it also has a config file for each language that basically allows you to add any bad functions (or other text) that you want to search for. It attempts to find phrases within comments that can indicate broken code and it provides stats and a pie chart (for the entire codebase and for individual files) showing relative proportions of code, whitespace, comments, '€˜ToDo'€™ style comments and bad code.

I've tried to produce something which searches intelligently for buffer overflows and signed/unsigned comparison in C, violations of OWASP recommendations in Java code, etc.

Current version: 2.1.0

VisualCodeGrepper V2.1.0 Web Site

KEEP ME UPDATED

Other Useful Business Software

The Sight of Sound Icon

­ Improve VoIP Visibility from SIP to RTP

The Sight of Sound Icon
Cloud­based voice solutions are common in enterprise networks and frustrating for operations teams to manage. Simplify VoIP monitoring by having a proactive analysis of on-prem, hybrid and UCaaS voice services. Try the ThousandEyes VoIP monitoring solution today, free.

User Ratings

★★★★★
★★★★
★★★
★★
2
2
0
0
0
ease 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 4 / 5
features 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 4 / 5
design 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 4 / 5
support 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 3 / 5
Write a Review

User Reviews

  • 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    good

    Posted 12/14/2016
  • 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    Thank you for the excellent work. I tried reverse engineering v 1.6 to support CLI so I could automate scans, but seems like v2.0 already supports it (haven't tried it yet though). When Microsoft CAT.NET went to oblivion, and with commercial tools are skyrocketing prices - VisualCodeGrepper is a viable and easy to use alternative! Will try v 2.0 at my earliest and share feedback. btw, VisualCodeGrepper is also mentioned on checkmarx blog under the title 'The Ultimate List of Open Source Static Code Analysis Security Tools'.

    Posted 11/19/2014
  • 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    Looks good! Can we have access to the source code ? The previous comment on the CI server is very pertinent, and I'd like to take a look and maybe provide a patch for it.

    Posted 11/27/2013
  • 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    Today, most of modern projects are using CI system, you offer a good project, thank you. But your app are Desktop, that means it cannot be integrated into CI system automatically. I assume nobody would like to call 'FindWindow' and 'SendMessage'.

    Posted 07/15/2013
Read more reviews

Additional Project Details

Intended Audience

Information Technology, Security

User Interface

Win32 (MS Windows)

Registered

2012-11-19

Thanks for helping keep SourceForge clean.

Screenshot instructions:
Windows
Mac
Red Hat Linux   Ubuntu

Click URL instructions:
Right-click on ad, choose "Copy Link", then paste here →
(This may not be possible with some types of ads)

More information about our ad policies
X

Briefly describe the problem (required):

Upload screenshot of ad (required):
Select a file, or drag & drop file here.

Please provide the ad click URL, if possible:

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

JavaScript is required for this form.

No, thanks