Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
-
Updated
Aug 13, 2026 - Scala
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
MATE is a suite of tools for interactive program analysis with a focus on hunting for bugs in C and C++ code using Code Property Graphs.
Code Property Graph (CPG) frontend for binary applications and libraries.
Codyze is a static analyzer for Java, C, C++ based on code property graphs
Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various graph databases.
The Cloud Property Graph is based on a Code Property Graph and tries to connect static code analysis and Cloud runtime assessment.
A static analysis tool for Java programs, based on the theory of code property graphs.
A Python implementation of a language-agnostic Code Property Graph
Succinct Compositional Program Graph (SCPG) static analysis engine & 14-diagram UML generator in Rust.
Neo4J visualisation tool for the Code Property Graph
Examples of how to use Plume
Static analysis tool that extracts architecture data from Kubernetes repos, builds multi-language code property graphs (Go, Python, TS, Rust), and runs security/architecture queries with taint analysis
A Demo Program of Security Patch Identification with Graph Neural Networks.
chennai (chen N ai) is a hybrid AI agent and a terminal user interface for static analysis, data-flow tracing, and AI-assisted code and security analysis.
Lab 04 Big Data project: incremental Code Property Graph streaming pipeline with Kafka, Neo4j, MongoDB, Spark Structured Streaming, and Jupyter Book evidence.
Ultra-fast open-source code security scanner. Finds vulnerabilities across 8 languages (Rust, Go, Python, JS, TS, Java, C, C++) using SAST + taint analysis + LLM verification — fewer false positives, faster audits. Outputs Sigstore-signed SARIF, SBOM, and OpenVEX bundles for supply-chain compliance.
Bounded Joern CPG tools for Codex and MCP coding agents
Multi-engine SAST scanner that traces tainted data source-to-sink across JS/TS, Python, Go, PHP and Ruby — with AI triage over MCP.
Add a description, image, and links to the code-property-graph topic page so that developers can more easily learn about it.
To associate your repository with the code-property-graph topic, visit your repo's landing page and select "manage topics."