codefit-cli/codefitCLI + MCP server that audits what AI-generated code hides: security risks, algorithmic complexity, DB quality & code review.
Go★ 0Jul 22, 2026
npm54Moderatehealth index
hamr0/litectxAgent memory + every context-engineering primitive (write / select / compress / isolate) in one importable library. Ranked recall with activation decay over SQLite/FTS5. One production dependency (better-sqlite3).
JavaScript★ 2↓ 3,664/moJul 18, 2026
malikov73/flakylintStatic analysis for flaky Go tests — catches flaky-test patterns before they flake in CI
Go★ 1Jul 21, 2026
Packagist54Moderatehealth index
spiral/tokenizer[READ ONLY] Locate available classes by parent, interface or trait. Subtree split of the Spiral Tokenizer component (see spiral/framework)
PHP★ 18↓ 425.3K/moJul 13, 2026
Packagist54Moderatehealth index
staabm/phpstan-baseline-analysisAnalyzes PHPStan baseline files and creates aggregated error trend-reports
PHP★ 84↓ 6,561/moJul 22, 2026
Packagist53Moderatehealth index
PHPCSStandards/PHPCSDevCSExternal ruleset for PHP CodeSniffer intended for use by sniff developers
Mixed★ 9↓ 8,686/moJul 21, 2026
PyPI · Go · Maven +153Moderatehealth index
nikitatsym/tackboxError-handling lint for Go, Python, Java, JS/TS, Svelte: every failure must report, propagate, or explain itself. Agent hook + pre-commit + CI.
Python · Go · Java★ 0↓ 1,088/moJul 15, 2026
Packagist53Moderatehealth index
php-stubs/woocommerce-stubsWooCommerce function and class declaration stubs for static analysis
PHP★ 95↓ 212.1K/moJul 16, 2026
npm53Moderatehealth index
sudoeren/arhuslocal-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2,972/moJul 17, 2026
PyPI · npm53Moderatehealth index
wang-jie-git/moatAI Coding Gatekeeper — Zero-config, real-time guardrails for AI-generated code. 零配置AI编码守门员,实时拦截架构/安全/回归问题。
Python · HTML★ 1↓ 2,206/moJul 19, 2026
Packagist52Moderatehealth index
staabm/phpstan-psr3FIG PSR3 PHPStan rules
PHP★ 23↓ 176.5K/moJul 22, 2026
typelate/checkType checking static analysis for Go templates.
Go★ 3Jul 20, 2026
PyPI52Moderatehealth index
vishnu-77/seccheckerNo repository description published.
Python★ 1Jul 22, 2026
Packagist51Moderatehealth index
AxeWP/WPGraphQL-Coding-StandardsPHP_Codesniffer ruleset (sniffs) for the WPGraphQL plugin ecosystem
Mixed★ 11↓ 4,087/moJul 21, 2026
crates.io51Moderatehealth index
doraemonkeys/sloc-guard🛡️ High-performance Rust CLI that enforces SLOC limits and directory structure rules to prevent code bloat — unlike counters, sloc-guard enforces them
Rust★ 21↓ 31/moJul 17, 2026
npm51Moderatehealth index
sshworld/rosterDoes your agent earn its context? Static analyzer for AI agent rosters — overlap, harness gaps, context cost.
TypeScript · Shell★ 1↓ 2,237/moJul 16, 2026
Packagist51Moderatehealth index
staabm/side-effects-detectorAnalyzes php-code for side-effects.
PHP★ 164↓ 9.7M/moJul 22, 2026
PyPI50Moderatehealth index
mimfort/rag_for_gitAI pull-request reviewer: hybrid RAG + a code graph + Claude Code. Whole-repo context, inline GitHub comments grounded on exact code. MCP server + Claude Code plugin.
Python★ 18↓ 5,377/moJul 15, 2026
npm50Moderatehealth index
mleoca/ucnUniversal Code Navigator
JavaScript★ 1↓ 2,153/moJul 16, 2026
Go · PyPI49At riskhealth index
Zayan-Mohamed/secscanSecScan is a fast, configurable secret scanning tool written in Go that detects API keys, tokens, credentials, and high-entropy secrets across source code and full Git history. Built for developers and CI pipelines, with strong defaults and low false positives.
Go · Shell · PowerShell★ 4Jul 20, 2026
artur-sulej/excellent_migrationsAn Elixir tool for checking safety of database migrations.
Elixir★ 295↓ 108.9K/moJul 17, 2026
PyPI49At riskhealth index
rubik/radonVarious code metrics for Python code
Python★ 1,997↓ 5.2M/moJul 21, 2026
zizmorcore/zizmorStatic analysis for GitHub Actions
Rust★ 5,886Jul 20, 2026
cloverrose/rpcguardrpcguard checks if connect-RPC endpoint method is implemented properly
Go★ 0Jul 21, 2026
criticaldeveloper/critical-gateNo repository description published.
TypeScript★ 1↓ 3,922/moJul 16, 2026
crates.io48At riskhealth index
eezz4/zzopDeterministic cross-repo contract analysis you can gate CI on — joins frontend calls to backend routes across repo boundaries and flags drift (typo'd path, version skew, dead endpoint). Also a multi-language SAST/architecture engine (TS/JS, Prisma, Java), extensible via adapters. Rust core, npm CLI/SDK.
Rust★ 1Jul 23, 2026
maclevison/cliquetThe quality ratchet for TS/JS: 9 zero-config gates against a versioned baseline — quality can only improve, never regress.
TypeScript★ 1↓ 2,177/moJul 18, 2026
Packagist42At riskhealth index
michaelmeneses/moodle-stubsPHP stubs for Moodle LMS - classes, functions, constants, and global variables for IDE and static analysis support
Mixed★ 1↓ 2,316/moJul 19, 2026
taq25/templ-lintSecurity linter for a-h/templ: detects XSS-prone htmx / Alpine.js usage by parsing .templ files directly with parser/v2
Go★ 0Jul 17, 2026
Go · crates.io · npm41At riskhealth index
tejaswini4119/phishvaultA Collabarative Project of developing and deploying a secure and intelligent platform designed to help users investigate, manage, and analyze potentially malicious URLs.
Go · TypeScript · Rust★ 2Jul 17, 2026