Untrusted input flow
SQL, OS command, code execution, path traversal and SSRF: the engine follows the input across functions and files, and shows every hop up to the dangerous call.
Misbah is a source code review platform for security auditors and inspection teams. It maps how untrusted data moves through the code under review and turns each risk into documented evidence — file, line, path and the rule behind it — while everything, from the client’s code to the final findings, remains on your own machine.
Every finding tells its own story: where the data entered, how it travelled, and where it became exploitable — laid out on the code itself, ready to verify and ready to present.
Behind every conclusion is a rule you can open, read and cite. When a client asks why, the answer is on screen — and every rule can be edited or disabled, with the set extending through new rules to fit the scope of each engagement.
The whole assessment on one screen: severities, CWE classes and the timing of every stage — the executive summary, before you write it.
Unfamiliar code stops being a blank page: discovered sources, the API surface and sensitive locations come together in one view that points the review to what matters first.
SQL, OS command, code execution, path traversal and SSRF: the engine follows the input across functions and files, and shows every hop up to the dangerous call.
Data one request writes to a database, a file or a session, and another reads back. The path is followed through the store and the load, not only within a single request.
277 real provider key and credential formats, with an entropy gate that drops documentation keys and placeholders instead of burying you in them.
73 rules over JSON, YAML, XML, TOML, INI, .env and .properties: disabled certificate verification, wide-open CORS, debug modes in production, keys written into config.
An inventory of the crypto calls in your code — algorithm, mode, key length — then a control-by-control verdict against NCS-1:2020, the Saudi NCA’s national cryptographic standard.
Unescaped output across ten template dialects: Razor, Twig, Jinja, Go, Vue, ERB, JSP, Handlebars, Jelly and Freemarker.
Not just a dangerous call: the engine looks for the object chain reachable from an untrusted deserialize all the way to a real execution.
A complete, proven path: a known source reaching an unambiguous sink, with every hop between them shown by file and line.
A real path with a weaker end — a broader source, or a sink that depends on context. It deserves a read, not an alarm.
Attack surface recognised by presence, not by flow: a dangerous call or an entry point, with no traced path. Counted and shown separately, never folded into the findings.
The tier is not decoration: the engine separates what it proved a complete path for from what it merely recognised as attack surface, so a confirmed vulnerability is never mixed into a list of things that need a human read.
A review does not end at the screen: one audience wants a document to open and send, another wants the findings inside its own tools, and a platform wants something it can read mechanically. All five formats come out of one scan with one command, and none of them is an abridged summary — every finding carries its source, its sink and every step between them.
A self-contained document that opens in the browser and is sent as it is — for management and the audit file.
Markdown that drops into a merge request, a ticket or a wiki with no manual formatting.
SARIF 2.1.0 uploads straight into code scanning on GitHub or GitLab, so findings appear on the very lines of the diff.
Every finding with its complete path, plus the exact configuration the engine ran with — for your tooling and dashboards.
One row per finding: class, severity, file and line — for sorting and follow-up.
The code under review opens locally, read-only; nothing ever leaves your machine.
A flow model of the project is built, and every rule is weighed against its sensitive paths.
Findings arrive ranked by severity and confidence, each with its evidence already attached.
Write to us for an evaluation build that runs on your own machines, or a guided walkthrough on sample code.
sales@safina.saThe blocks above are not images; they are the application interface itself, taken from a running build against real scan results.
© 2026 Safina — Misbah