SAST

Coverage

XEIZE statically analyzes source code across multiple languages and frameworks. The languages the engine can parse and the vulnerabilities the default SAST rule pack can detect are different aspects of coverage. Actual detection depends on the installed engine and rule pack versions, the enabled rules, and the files included in the analysis.

Default SAST rule pack

The default SAST rule pack analyzes the following languages and file formats:

  • C
  • C++
  • C#
  • Go
  • Java
  • Kotlin
  • PHP
  • Python
  • Swift
  • JavaScript/JSX
  • TypeScript/TSX
  • HTML/XHTML

Major frameworks and runtimes

The following are key frameworks and runtimes covered by the rules and input-tracking models. This does not imply equal detection coverage for every API or version of each framework.

Category Coverage
Java/Kotlin Servlet, Spring MVC/Boot, WebFlux, AWS Lambda HTTP, and others
JavaScript/TypeScript Node.js/Express, Next.js, Koa, Hono, Fastify, AWS Lambda HTTP, and others
Python Django/DRF, FastAPI/Starlette, Flask, and others
Go net/http, Echo, Gin, and others
C# ASP.NET Core and others
Frontend/templates React/TSX, jQuery, HTML/XHTML, JSF/XHTML, and others