/sql-injection-scanner

a sast tool for detecting sql injection vulnerabilities in php codebases, intern project of summer 2019 at JotForm.

Primary LanguagePHP

sql-injection-scanner

Simple tool to scan a PHP code to look for potential injection vulnerabilities. Made using nikic/PHP-Parser, written in PHP.

to run: php scan.php PATH/TO/YOUR_PROJECT/

notice the trailing "/". target has to be a directory.

dependencies

https://www.php.net/manual/en/intro.ds.php

https://github.com/nikic/PHP-Parser

please note

that this tool is far from complete and false positive/negatives are quite common.