$npx skillfedfor your agent

flawfinder

a program that examines source code looking for security weaknesses

With conditionsPyPI TestingReleased May 2026130.6K downloads / moGPL-2.0+Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — flawfinder-2.0.20-py2.py3-none-any.whl
v2.0.20 · released 2026-05-17 · Python >=2.7

Yes, if you maintain or audit C/C++ code. Flawfinder is production-stable, has no install friction, carries no known vulnerabilities, and fills a specific niche in static security analysis. The GPL-2.0+ copyleft license is a consideration for proprietary projects but poses no barrier to open-source use.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low install friction with no runtime dependencies.
  • Active maintenance status and production-stable classifier indicate ongoing support.

License · maintenance · safety

GPL-2.0+ (copyleft) — Released under GPL-2.0+, a copyleft license. Use is free for open-source projects; proprietary or closed-source use requires careful license compliance review.

last release 2026-05-17 (89 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 130,588 downloads/mo, #11,637 on PyPI

Verify before relying

pip install flawfinder
flawfinder /path/to/source/code
  • Whether the tool integrates with common CI/CD platforms or build systems beyond command-line use
  • Performance characteristics on large codebases or typical scan times
  • Specifics of which C/C++ standards or dialects are supported
Same gist for agents: .md · .json

What it is and what it does

Flawfinder is a command-line static analysis tool that examines C and C++ source code to detect potential security weaknesses. It works by scanning code without executing it, identifying patterns and constructs known to be security risks, then ranking findings by severity to help developers prioritize fixes.

The tool runs as a standalone Python application with no external runtime dependencies, making it straightforward to integrate into development workflows or security scanning pipelines. It supports Python 2.7 and Python 3, and is classified as production-stable with active maintenance.

Use it for

  • Scan legacy C/C++ codebases before security audits to identify and prioritize known vulnerability patterns
  • Integrate into CI/CD pipelines to flag potential security issues in pull requests before code review
  • Perform initial security triage on unfamiliar C/C++ projects to understand baseline risk areas
  • Verify that security fixes have addressed flagged issues in previously scanned code

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you maintain or audit C/C++ code.

Flawfinder is production-stable, has no install friction, carries no known vulnerabilities, and fills a specific niche in static security analysis. The GPL-2.0+ copyleft license is a consideration for proprietary projects but poses no barrier to open-source use.

Install

flawfinder on PyPI

Before you install

Low install friction with no runtime dependencies. Active maintenance status and production-stable classifier indicate ongoing support.

License in practice

Released under GPL-2.0+, a copyleft license. Use is free for open-source projects; proprietary or closed-source use requires careful license compliance review.

Quickstart

pip install flawfinder
flawfinder /path/to/source/code

Verify before relying

  • Whether the tool integrates with common CI/CD platforms or build systems beyond command-line use
  • Performance characteristics on large codebases or typical scan times
  • Specifics of which C/C++ standards or dialects are supported

Package facts

LicenseGPL-2.0+ copyleft
Python supportSupports the current Python release >=2.7
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 89 days since the last release
First released
Downloads130,588 / month, #11,637 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: GNU General Public License v2 or later (GPLv2+)Natural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.6Topic :: SecurityTopic :: Software Development :: Build ToolsTopic :: Software Development :: Quality AssuranceTopic :: Software Development :: Testing

Evidence: flawfinder-2.0.20-py2.py3-none-any.whl

Tags

Capabilities
C/C++ security vulnerability scannersource code security analysisstatic analysis security flawsC++ code security checkeridentify security weaknesses in code
Topics
static-analysisc-cpp
PyPI keywords
analysissecurityanalyzer

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “source code security analysis”

  • flawfinderFlawfinder scans C/C++ source code to identify potential security…
  • trailmarkParses source code into a queryable graph of functions, classes,…
  • pyre-checkPysa is a static analysis tool that tracks data flows through Python…

Give your agent the search over MCP, or paste the wish link into any chat.

More Testing packages

pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo
virtualenv Worth it
PyPI · Libraries · released Aug 2026

virtualenv creates isolated Python environments where packages can be installed independently without affecting the system Python or other projects.

MITpure Python · 3.9+
532.9Mdownloads / mo
coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
pytest-asyncio Worth it
PyPI · Testing · released May 2026

pytest-asyncio is a pytest plugin that enables writing and running async test functions using the asyncio library, allowing developers to await code directly within test cases.

Install it if you write tests for any asyncio-based code.

Apache-2.0pure Python · 3.10+
275.9Mdownloads / mo
pytest-json-ctrf Worth it
PyPI · Testing · released Jul 2026

A pytest plugin that generates test reports in Common Test Report Format (CTRF) as JSON, compatible with pytest-xdist and pytest-playwright for distributed and browser-based testing.

Install it if you need CTRF-formatted test output for CI/CD integration or cross-tool reporting.

MITpure Python · 3.8+
273.0Mdownloads / mo

See also dodgy · mr-proper · zizmor · scanoss · libsast · bc-detect-secrets · cisco-ai-skill-scanner · trufflehog3 · slither-analyzer · cwe2

Further reading