Find Security Bugs

The FindBugs plugin that help security audit on Java web application.

(Last updated: 2nd January 2015)

56 different bug patterns

Include bug pattern detection for various vulnerability types.

Support your frameworks and libraries

Cover popular frameworks including Spring-MVC, Struts, Tapestry and many more.

Integrate with your IDE

Plugins are available for Eclipse, IntelliJ and NetBeans. Command line integration is available with Ant and Maven.

Continuous integration

Can be used with systems such as Jenkins and SonarQube.

OWASP TOP 10 and CWE coverage

Extensive references are given for each bug patterns with references to OWASP Top 10 and CWE.

Open for contributions

The project is open-source and is open for contributions.