High false positive detection of security vulnerabilities
Muhammad Nadeem, Byron J. Williams, Edward B. Allen · 2012
Static code analysis is an emerging technique for secure software development that analyzes large software code bases without execution to reveal potential vulnerabilities present in the code. These vulnerabilities include but are not limited to SQL injections, buffer overflows, cross site scripting, improper security settings, and information leakage.