Coverage
XEIZE statically analyzes source code across multiple languages and frameworks. The languages the engine can parse and the vulnerabilities the default SAST rule pack can detect are different aspects of coverage. Actual detection depends on the installed engine and rule pack versions, the enabled rules, and the files included in the analysis.
Default SAST rule pack
The default SAST rule pack analyzes the following languages and file formats:
- C
- C++
- C#
- Go
- Java
- Kotlin
- PHP
- Python
- Swift
- JavaScript/JSX
- TypeScript/TSX
- HTML/XHTML
Major frameworks and runtimes
The following are key frameworks and runtimes covered by the rules and input-tracking models. This does not imply equal detection coverage for every API or version of each framework.
| Category | Coverage |
|---|---|
| Java/Kotlin | Servlet, Spring MVC/Boot, WebFlux, AWS Lambda HTTP, and others |
| JavaScript/TypeScript | Node.js/Express, Next.js, Koa, Hono, Fastify, AWS Lambda HTTP, and others |
| Python | Django/DRF, FastAPI/Starlette, Flask, and others |
| Go | net/http, Echo, Gin, and others |
| C# | ASP.NET Core and others |
| Frontend/templates | React/TSX, jQuery, HTML/XHTML, JSF/XHTML, and others |