| CARVIEW |
Select Language
HTTP/2 200
server: GitHub.com
content-type: text/html; charset=utf-8
last-modified: Tue, 17 Jun 2025 04:05:31 GMT
access-control-allow-origin: *
etag: W/"6850e98b-4164"
expires: Sun, 18 Jan 2026 10:47:05 GMT
cache-control: max-age=600
content-encoding: gzip
x-proxy-cache: MISS
x-github-request-id: EFE6:ECF0:1CAD76:21F044:696CB7CD
accept-ranges: bytes
age: 0
date: Sun, 18 Jan 2026 10:37:05 GMT
via: 1.1 varnish
x-served-by: cache-bom-vanm7210028-BOM
x-cache: MISS
x-cache-hits: 0
x-timer: S1768732625.164638,VS0,VE212
vary: Accept-Encoding
x-fastly-request-id: 7ac0c96fe80767a60446053738c948babbeb6709
content-length: 3897
Find Security Bugs
{} Find Security Bugs
The SpotBugs plugin for security audits of Java web applications.
(Last updated: April 20th, 2025)-
Spread the word:
Tweet
-
Follow the project:
Visit the GitHub project
Features
144 bug patterns
It can detect 144 different vulnerability types with over 826 unique API signatures.
Support your frameworks and libraries
Cover popular frameworks including Spring-MVC, Struts, Tapestry and many more.
Integrate with your IDE
Plugins are available for Eclipse, IntelliJ / Android Studio and NetBeans. Command line integration is available with Ant and Maven.
OWASP TOP 10 and CWE coverage
Extensive references are given for each bug patterns with references to OWASP Top 10 and CWE.
Open for contributions
The project is open-source and is open for contributions.