Java Vulnerability Scanner for VS Code

A VS Code extension that detects security vulnerabilities in Java code using pattern matching and static analysis.
Features
- Detects common Java security vulnerabilities:
- SQL Injection
- Command Injection
- XSS vulnerabilities
- Insecure deserialization
- Weak cryptographic algorithms
- Integrates with SpotBugs for advanced analysis
- Real-time scanning on file save
- Detailed vulnerability explanations
Installation
- Open VS Code
- Go to Extensions view (
Ctrl+Shift+X)
- Search for "Java Vulnerability Scanner"
- Click Install
Usage
- Open a Java file
- Use the command palette (
Ctrl+Shift+P) and run "Scan for Java Vulnerabilities"
- Or let it automatically scan when you save files
Configuration
Add these settings to your settings.json:
{
"javaVulnerabilityScanner.scanOnSave": true,
"javaVulnerabilityScanner.spotBugsPath": "/path/to/spotbugs"
}
| |