Find Security Bugs

The FindBugs plugin that help security audit on Java web application.

(Last updated: 3rd April 2015)

Features

63 different bug patterns

Include bug pattern detection for various vulnerability types.

Support your frameworks and libraries

Cover popular frameworks including Spring-MVC, Struts, Tapestry and many more.

Integrate with your IDE

Plugins are available for Eclipse, IntelliJ, Android Studio and NetBeans. Command line integration is available with Ant and Maven.

Continuous integration

Can be used with systems such as Jenkins and SonarQube.

OWASP TOP 10 and CWE coverage

Extensive references are given for each bug patterns with references to OWASP Top 10 and CWE.

Open for contributions

The project is open-source and is open for contributions.

Screenshots

Eclipse

IntelliJ / Android Studio

Sonar Qube