Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Brakeman serves as a security assessment tool tailored for Ruby on Rails applications. In contrast to several typical web security scanners, Brakeman analyzes the actual source code of your application rather than requiring a full application stack setup. After scanning the application code, it generates a comprehensive report detailing all identified security vulnerabilities. Installation is straightforward, with Brakeman needing no additional setup or configuration—simply launch it. Since it operates solely on the source code, Brakeman can be executed at any phase of development; for instance, you can create a new application with "rails new" and promptly evaluate it using Brakeman. By not depending on spidering techniques to explore site pages, Brakeman ensures a more thorough assessment of an application, including those pages that may be under development and not yet publicly accessible. This capability allows Brakeman to potentially identify security weaknesses before they can be exploited by malicious actors. As a tool specifically designed for Ruby on Rails applications, Brakeman adeptly verifies configuration settings against established best practices, thereby enhancing overall application security. Its efficiency and ease of use make it an invaluable resource for developers focusing on secure coding practices.

Description

Visual Expert is a static code analyzer for Oracle PL/SQL, SQL Server T-SQL and PowerBuilder. It identifies code dependencies to let you modify the code without breaking your application. It also scans your code to detect security flaws, quality, performance and maintenability issues. Identify breaking changes with impact analysis. Scan the code to find security vulnerabilities, bugs and maintenance issues. Integrate continuous code inspection in a CI workflow. Understand the inner workings and document your code with call graphs, code diagrams, CRUD matrices, and object dependency matrices (ODMs). Automatically generate source code documentation in HTML format. Navigate your code with hyperlinks. Compare two pieces of code, databases or entire applications. Improve maintainability. Clean up code. Comply with development standards. Analyze and improve database code performance: Find slow objects and SQL queries, optimize a slow object, a call chain, a slow SQL query, display a query execution plan.

API Access

Has API Yes 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

GitHub Yes 
Apache Subversion No 
Azure DevOps Server No 
CodeFactor Yes 
Dradis Yes 
Git No 
GitLab No 
JSON Yes 
Jenkins No 
Nucleus Yes 
Oracle Database No 
PowerBuilder No 
RuboCop Yes 
Ruby Yes 
Ruby on Rails Yes 
SQL Server No 
Seeker Yes 
ThreadFix Yes 
Visual Studio No 

Integrations

GitHub Yes 
Apache Subversion Yes 
Azure DevOps Server Yes 
CodeFactor No 
Dradis No 
Git Yes 
GitLab Yes 
JSON No 
Jenkins Yes 
Nucleus No 
Oracle Database Yes 
PowerBuilder Yes 
RuboCop No 
Ruby No 
Ruby on Rails No 
SQL Server Yes 
Seeker No 
ThreadFix No 
Visual Studio Yes 

Pricing Details

No price information available.
Free Trial No 
Free Version Yes 

Pricing Details

$495 per year
Perpetual license available
Floatting license available
Free Trial Yes 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based No 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person No 

Vendor Details

Company Name

Brakeman

Founded

2014

Website

brakemanscanner.org

Vendor Details

Company Name

Novalys

Founded

1998

Country

France

Website

www.visual-expert.com

Product Features

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Vulnerability Scanners

Asset Discovery No 
Black Box Scanning No 
Compliance Monitoring No 
Continuous Monitoring No 
Defect Tracking No 
Interactive Scanning No 
Logging and Reporting No 
Network Mapping No 
Perimeter Scanning No 
Risk Analysis No 
Threat Intelligence No 
Web Inspection No 

Product Features

Application Development

Access Controls/Permissions No 
Code Assistance No 
Code Refactoring Yes 
Collaboration Tools Yes 
Compatibility Testing No 
Data Modeling No 
Debugging No 
Deployment Management No 
Graphical User Interface No 
Mobile Development No 
No-Code No 
Reporting/Analytics Yes 
Software Development Yes 
Source Control No 
Testing Management No 
Version Control No 
Web App Development No 

Performance Testing

API Testing No 
Benchmarking No 
Cross Browser Testing No 
Debugging No 
Historical Reporting No 
Load Testing No 
Mobile Testing No 
Parallel Testing No 
Regression Testing No 
UI Testing No 
Web Testing No 

Source Code Management

Access Controls/Permissions No 
Bug Tracking No 
Build Automation No 
Change Management Yes 
Code Review Yes 
Collaboration No 
Continuous Integration Yes 
Repository Management No 
Version Control No 

SQL Server

CPU Monitoring No 
Credential Management No 
Database Servers No 
Deployment Testing No 
Docker Compatible Containers No 
Event Logs No 
History Tracking No 
Patch Management No 
Scheduling No 
Supports Database Clones No 
User Activity Monitoring No 
Virtual Machine Monitoring No 

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Static Code Analysis

Analytics / Reporting Yes 
Code Standardization / Validation Yes 
Multiple Programming Language Support Yes 
Provides Recommendations Yes 
Standard Security/Industry Libraries Yes 
Vulnerability Management Yes 

Vulnerability Management

Asset Discovery No 
Asset Tagging No 
Network Scanning No 
Patch Management No 
Policy Management No 
Prioritization No 
Risk Management No 
Vulnerability Assessment Yes 
Web Scanning No 

Alternatives

Alternatives

YAG-Suite Reviews

YAG-Suite

YAGAAN
SonarQube Server Reviews

SonarQube Server

SonarSource
PT Application Inspector Reviews

PT Application Inspector

Positive Technologies
SonarQube Cloud Reviews

SonarQube Cloud

SonarSource