Product
SAST Coverage & Rules Zero-Day Discovery Practice Lab (CTF) Download
Compliance
Compliance Hub OWASP Top 10 CWE Top 25 PCI DSS 4.0.1 MISRA C / C++ 2023 AUTOSAR C++14 ISO 26262 SEI CERT
Compare
vs All SAST Tools vs Coverity vs Veracode vs Snyk vs Mythos AI vs GPT-5.4 Cyber Get it free
COMMUNITY EDITION  ·  FREE FOREVER  ·  RUNS OFFLINE

A serious SAST scanner,
free for the world.

33,900+ detection rules across 17 languages, a deterministic 217-rule zero-day discovery suite, an abstract interpreter for embedded C/C++, AI false-positive triage, and one-click compliance reports — given freely to the community. Free to use, free to reproduce, free to adopt. No licensing restrictions.

No license keys, ever 17 languages, one engine Air-gapped, zero telemetry
phantomyerra - scan ./src
$ phantomyerra scan ./src --all
17 languages · 33,937 rules · zero-day suite armed
ok 1,284 files analyzed in 4.2s
 
CRITICAL CWE-89 SQL Injection
src/api/users.c:142
142 | snprintf(q, 256, "SELECT * FROM u WHERE id=%s", req->id);
source: req->id // HTTP param, untrusted
sink: sqlite3_exec(db, q) at users.c:147
MISRA C:2023 · CERT C STR · confidence 0.94
AI review: CONFIRMED exploitable
 
ok report.docx · report.sarif · CRA appendix written
33,937
detection rules
17
languages
217
zero-day discovery rules
1,003
cross-language framework rules
PhantomYerra Community Edition
Free to use Free to reproduce Free to adopt No licensing restrictions

Built as a university project and released to the world as a community service — for students, researchers, teachers and anyone who wants stronger, safer code. Take it, run it, share it, build on it. It belongs to everyone.

One engine

Everything a code-security team needs, in one scan.

SAST, software-composition analysis, SBOM, secret detection and infrastructure-as-code, run together on every commit. No agents, no cloud upload, no license keys — ever.

Traced, not guessed

Every finding ships with a source-to-sink taint chain, the abstract-interpreter justification, a CWE / MISRA / CERT mapping, and an AI false-positive verdict. No keyword-match noise.

10,334

Native C/C++ rules

Cross-translation-unit taint, interval/nullness/resource/taint and Pentagon polyhedral lattices, plus 100% canonical MISRA C:2023 (200), MISRA C++:2023 (186), AUTOSAR C++14 (423), CERT C (172) and CERT C++ (86) — the kind of depth safety-critical teams need, free for everyone.

SCA, SBOM, secrets, deep IaC

Dependency reachability across every ecosystem (so you fix what actually executes), CycloneDX/SPDX SBOMs, secret detection, and a deep native IaC suite: Terraform, Kubernetes & Helm, CloudFormation, Ansible, Pulumi, OPA/Rego and Dockerfiles.

AI triage + autofix

Review every finding before it reaches the report, then generate a fix for each one and verify it - with the compile loop where a toolchain exists, or with AI - across every supported language.

Air-gapped, pure-Python

Runs fully offline with zero telemetry. Nothing leaves the host unless you opt into an external AI provider for triage.

Zero-day discovery

Not just known CVEs. Novel bug classes.

Traditional SAST matches patterns for bug shapes that are already named. PhantomYerra runs a deterministic 217-rule zero-day discovery suite on every scan, across 7 dedicated engines and all 17 languages - finding the exploit primitives that turn into tomorrow's CVE, with a line-level location and a reproducible trace.

YerraIntelliTraceCross-file interprocedural taint
YerraRaceTrackConcurrency, TOCTOU, deadlock
YerraGadgetHunterDeserialization gadget chains
YerraCryptoSeerCrypto-oracle discovery
YerraAuthTracerAuth-chain bypass discovery
YerraSupplyWatchSupply-chain compromise patterns
YerraZeroDayAIAI novel-class, validated in-code
0 false positivesOn clean public corpora
Open & honest

Transparent, reproducible, and yours to verify.

No black boxes and no marketing math. PhantomYerra runs a deterministic, source-traced discovery suite on your whole tree — offline, reproducible, with a file and line for every finding. Here's how it lines up against the tools people ask about — written honestly, gaps and all.

17 languages, one engine

Every major language, at serious depth — free for all.

C 5,768 C++ 4,566 JavaScript / TS 4,307 .NET / C# 3,197 Java 3,130 PHP 1,604 Rust 1,439 Go 1,109 Ruby 1,001 Kotlin 1,001 Swift 950 Shell 812 Groovy 805 Python 750 Scala 655 Dart 556 Cross-language framework pack 1,003 Zero-day discovery 217
Compliance built in

One click from scan to audit-ready report.

Every finding is mapped to the standards your auditors ask for, and exported as a compliance appendix in DOCX, PDF, HTML, XLSX and SARIF. The EU Cyber Resilience Act is ready today.

Also free · learn by doing

Learn to hack & defend in the PhantomYerra Practice Lab.

A free, hands-on security playground that runs right in your browser — the OWASP Top 10 across 8 tracks, a guided Academy, a safe Linux shell emulator, an injection lab (SQLi & more), an AI mentor, and capture-the-flag challenges. Built for students and the curious, as part of the same community mission. No install, no cost, no licensing.

OWASP Top 10Web, API, Mobile, LLM, IoT, Cloud, CI/CD, OT
Academy55 guided lessons, zero to hero
Linux LabSafe simulated shell & commands
Injection LabSQLi, NoSQL, SSTI, XSS & more
AI MentorHints & coaching, offline
Capture the flagXP, badges, certificates

Free to use. Free to reproduce. Free to adopt.

One offline engine for SAST, SCA, SBOM, secrets and IaC across 17 languages — with a zero-day discovery suite, an abstract interpreter for embedded C/C++, and compliance reporting built in. No license keys, no sign-up, no strings. A university project, given to the world.