Skip to main content
Codepure’s Static Application Security Testing (SAST) engine is designed to seamlessly integrate into your development workflow, providing fast and accurate security analysis directly within your codebase. Below is a comprehensive breakdown of the programming languages, file extensions, and key frameworks officially supported by our security engine.

Language Support Matrix

LanguageFile ExtensionsKey Frameworks & Technologies Supported
.NET / C#.csWeb: ASP.NET Core, Minimal API, WebForms, MVC/Razor.
Data: Entity Framework, SqlCommand, SQLite, MySQL, PostgreSQL, Oracle, DB2, Firebird, Sybase.
Other: Active Directory, BinaryFormatter, JsonSerializer.
Java.javaWeb: Spring Boot, JAX-RS, Servlets.
Data: Hibernate/JPA, JDBC.
Other: XML (SAXParser, DocumentBuilder), Deserialization (ObjectInputStream), LDAP, HttpClient.
JavaScript / TypeScript.js, .ts, .jsx, .tsxWeb: Express.js, NestJS, Next.js, React (JSX/DOM).
Data: Mongoose, Sequelize, Knex.
Other: Axios, Fetch, Got, child_process, fs.
PHP.phpWeb: Laravel, Symfony, Native Superglobals.
Data: PDO, Eloquent ORM, MySQLi, PostgreSQL, SQLite, DB2.
Other: cURL, XPath, LDAP, native shell execution.
Python.pyWeb: Django, Flask, FastAPI/Asyncio, GraphQL (Saleor).
Data: Django ORM, SQLite.
Other: Requests, Httpx, Urllib, Subprocess, Pickle, PyYAML, lxml.
Ruby.rb, .erbWeb: Ruby on Rails, Sinatra.
Data: Active Record, Sequel, Mongoid, Redis.
Other: Faraday, Typhoeus, Nokogiri, REXML, Marshal, JSON.
Go (Golang).goWeb: net/http, Gin, Echo, Fiber, html/template.
Data: database/sql, GORM, Sqlx, MongoDB (bson).
Other: os/exec, encoding/json, encoding/gob, encoding/xml, ldap.
Kotlin.kt, .ktsAndroid: Intents, URIs, Content Providers.
Web: Spring Boot Web.
Other: OkHttpClient, Android UI components.
Swift (iOS/macOS).swiftiOS: ViewControllers, UITextField, UISearchBar, WebViews, UIPasteboard.
Data: UserDefaults, CoreData (NSPredicate), FileManager.
Other: Alamofire, CryptoKit, OSLog, NSKeyedUnarchiver, Swift Package Manager.
Dart (Flutter).dartFlutter: UI TextControllers, WebViews.
Data: SQLite, Hive, SharedPreferences, FileCacheStore.
Other: Clipboard, Dart Crypto/Math (MD5, SHA1, Random).