Flawfinder
A command-line scanner that checks C and C++ source code for patterns associated with security weaknesses.
Open source (GPL-2.0-or-later)By David A. Wheeler
Compare Flawfinder with another product
Read the Flawfinder documentation
Alternatives
See all alternativesAbout Flawfinder
Flawfinder scans C and C++ source code for calls and patterns associated with potential security weaknesses, then sorts its findings by risk level. It can produce text, HTML, CSV and SARIF output.
It is an intentionally simple static analysis aid, not a complete security review. The official site describes installation through Python and pip, and notes that Windows use is supported through Cygwin.
Strengths
- Ranks potential findings by risk level
- Can generate HTML, CSV and SARIF output
- Available through pip and distribution packages
Limitations
- Checks C and C++ source code
- Findings need investigation and do not replace a security review
Details
- Pricing
- FreeFree and open source under GPL-2.0-or-later.
- License
- GPL-2.0-or-later
- Developer
- David A. Wheeler
- Platforms
- Windows, macOS, Linux, Command line
- How it runs
- Downloadable app
- Best suited for
- Developers checking C and C++ code for common risky patterns
- Categories
- Security tools, Developer tools
- Last verified
- Added
- Provenance
- Selected from the Homebrew formula
- Sources