Skip to content
winfunc
SAST
Available

Find the vulnerabilities that are actually exploitable.

Multi-phase analysis follows attacker-controlled input through your application to the operation it can abuse. Every finding carries the trace, the evidence, and the fix.

  1. acme
  2. /billing-api
  3. /Vulnerabilities
  4. /WF-1042
Critical
Sourceroutes/invoices.ts:18
req.params.invoiceId
Sourceroutes/pdf.ts:31
req.query.invoice
1
Passed to the service without the caller's tenantinvoices.get(id)services/invoices.ts:42
2
Repository looks the invoice up by id alonerepo.findInvoice(id)repo/invoices.ts:71
Sinkrepo/invoices.ts:77
db.query("SELECT * FROM invoices WHERE id = $1", [id])

Cross-tenant invoice read through an unscoped lookup

CriticalCVSS 9.1
Weakness
CWE-639 · Authorization bypass
Confidence
97
Validation
Exploitable
Proof
Tenant A read tenant B's invoice in the sandbox
Finding · source to sinkIllustrative data
  1. Every place attacker-controlled input enters.
  2. Each hop is recorded with the code that carried the value.
  3. The dangerous operation, with no check on the path.
  4. Reproduced in an isolated sandbox before it reached you.
What it does

Capabilities.

  • Multi-phase analysis across the languages in your repository
  • Source-to-sink data-flow tracing, anchored to lines of code
  • Reproduction steps or proof-of-concept evidence where testing is in scope
  • CVSS vector and the rationale behind every severity
  • Confidence score for each finding
  • Authorization, tenant-boundary, and business-logic investigation
  • Concurrency, TOCTOU, and state-transition review
  • Duplicate detection with similarity scoring across scans
  • Status workflow from pending to validated, accepted, and resolved
  • Filtering by severity, confidence, revision, and status
Why it matters

Built for decisions, not queues.

01

Evidence before a decision

Each report ties the claim to affected code, prerequisites, and the evidence behind it. Observed behavior and inferred impact are labeled separately, so reviewers know exactly what was proven.

02

Source-to-sink tracking

Follow the path from untrusted input to a sensitive operation through the call graph, with the code recorded at each hop and every control that was checked along the way.

03

Business-logic awareness

Application context lets winfunc reason about roles, permissions, tenants, and money movement. That is where its public findings live: account takeovers, authorization bypasses, and payment-logic flaws.

04

Incremental and full scans

Audit a whole revision, or focus on changed files as the codebase moves. Findings are always pinned to the revision they were found in.

05

Lifecycle, not a list

Status tracking, validation notes, timestamps, and exports keep triage auditable from first signal to verified fix.

06

Language coverage

More than 25 languages, from C, C++, Rust, Go, and Zig to Java, Kotlin, C#, Python, Ruby, PHP, TypeScript, Swift, Dart, Solidity, Haskell, and Elixir. Coverage is not bounded by a rule set.

07

Exploit chains

Related findings are combined into chains, so a low-severity gadget that enables a critical path is reported as part of that path.

Continue the evaluation

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified