Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
-
Updated
Oct 7, 2026 - Scala
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
Succinct Compositional Program Graph (SCPG) static analysis engine & 14-diagram UML generator in Rust.
MATE is a suite of tools for interactive program analysis with a focus on hunting for bugs in C and C++ code using Code Property Graphs.
Code Property Graph (CPG) frontend for binary applications and libraries.
Codyze is a static analyzer for Java, C, C++ based on code property graphs
Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various graph databases.
The Cloud Property Graph is based on a Code Property Graph and tries to connect static code analysis and Cloud runtime assessment.
Open-source CPG-based interprocedural taint analysis + LLM triage, with a Ghidra-style audit workbench. Runs fully offline.
A static analysis tool for Java programs, based on the theory of code property graphs.
A Python implementation of a language-agnostic Code Property Graph
Neo4J visualisation tool for the Code Property Graph
Modernizr: agent skills for investigating legacy software with code property graphs, graph algorithms, and symbolic analysis.
Examples of how to use Plume
Static analysis tool that extracts architecture data from Kubernetes repos, builds multi-language code property graphs (Go, Python, TS, Rust), and runs security/architecture queries with taint analysis
chennai (chen N ai) is a hybrid AI agent and a terminal user interface for static analysis, data-flow tracing, and AI-assisted code and security analysis.
Compiler-precise code property graph for C, Python, and TypeScript, navigable over MCP — data- and taint-flow with source→sink witnesses, points-to, and guard/sink structure for security reasoning over source.
A Demo Program of Security Patch Identification with Graph Neural Networks.
KarsaSec is a high-performance, pluggable Static Application Security Testing (SAST) platform for multi-language codebases. Features an advanced AST-based CPG (Code Property Graph) query engine, local hybrid RAG security remediation, and autonomous AI-agent workflows with zero-trust guardrails.
To associate your repository with the code-property-graph topic, visit your repo's landing page and select "manage topics."