Flawfinder

A command-line scanner that checks C and C++ source code for patterns associated with security weaknesses.

Open source (GPL-2.0-or-later)By David A. Wheeler

Compare Flawfinder with another product

Read the Flawfinder documentation

Alternatives

See all alternatives

About Flawfinder

Flawfinder scans C and C++ source code for calls and patterns associated with potential security weaknesses, then sorts its findings by risk level. It can produce text, HTML, CSV and SARIF output.

It is an intentionally simple static analysis aid, not a complete security review. The official site describes installation through Python and pip, and notes that Windows use is supported through Cygwin.

Strengths

  • Ranks potential findings by risk level
  • Can generate HTML, CSV and SARIF output
  • Available through pip and distribution packages

Limitations

  • Checks C and C++ source code
  • Findings need investigation and do not replace a security review

Details

Pricing
FreeFree and open source under GPL-2.0-or-later.
License
GPL-2.0-or-later
Developer
David A. Wheeler
Platforms
Windows, macOS, Linux, Command line
How it runs
Downloadable app
Best suited for
Developers checking C and C++ code for common risky patterns
Last verified
Added
Provenance
Selected from the Homebrew formula

Report a wrong fact or a dead link on this listing