Skip to content
CAI
Software that uses CAICheck a score

nccgroup/sobelow

67.6

Adequate · 23 September 2026

4.3k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Sobelow is a static security analysis tool for Elixir and Phoenix applications that identifies vulnerabilities such as SQL injection, XSS, command injection, and remote code execution. It provides a modular scanning engine that detects risks in code, configuration, and dependencies, supporting multiple output formats including JSON and SARIF for CI/CD integration. The system is designed to help developers find and fix security issues early in the development lifecycle.

Features

Add BinToTerm check and deprecate File/Path check

Added a new security check for the insecure use of Erlang's \binary\_to\_term\ function, which can lead to memory exhaustion or code execution. The existing File/Path check has been deprecated as the related issues were addressed in OTP 21.

lib/sobelow/misc · medium confidence

Added RCE checks for Code.eval and EEx template evaluation

Sobelow now includes two new security findings for Remote Code Execution (RCE) vulnerabilities. The first, RCE.CodeModule, detects arbitrary code execution via Elixir's Code.eval\\ functions. The second, RCE.EEx, identifies insecure EEx template evaluation that could lead to code execution. Both checks are configured with low confidence when not in a controller context and can be ignored using the respective module names.

lib/sobelow/rce · high confidence

Added command injection checks for :os.cmd and System.cmd

New security checks have been added to detect command injection vulnerabilities in Erlang's :os.cmd and Elixir's System.cmd functions. The lib/sobelow/ci/os.ex and lib/sobelow/ci/system.ex modules now scan for these specific patterns, allowing users to identify potential command injection risks in their codebases.

lib/sobelow/ci · high confidence

Major refactoring of the vulnerability scanning engine and finding structure

The internal architecture for handling security findings has been completely rewritten. A new \Sobelow.Finding\ struct standardizes how vulnerabilities are stored and reported, enabling consistent output across JSON, TXT, and SARIF formats. This change introduces a centralized \FindingLog\ GenServer to aggregate results by severity (high, medium, low) and supports SARIF (v2.1.0) and Flycheck output formats. Additionally, the \Sobelow.Utils\ module has been expanded to include robust file discovery, application name detection, and template parsing, while the legacy \Utilsb\ module has been removed. These changes improve the reliability of the scanner and provide more structured, machine-readable reports for users and CI/CD pipelines.

lib/sobelow · high confidence

New DOS checks for unsafe atom conversions

Added three new Denial of Service (DOS) findings to detect unsafe atom creation, which can lead to memory exhaustion in Elixir applications. The new checks cover \String.to\_atom\, \List.to\_atom\, and binary-to-atom interpolation. Each finding is assigned a unique UID (11, 12, and 13 respectively) and can be ignored using the \-i\ flag with the specific finding type (e.g., \DOS.StringToAtom\).

lib/sobelow/dos · high confidence

New SQL injection checks for Ecto query and stream methods

Sobelow now includes dedicated checks for SQL injection vulnerabilities in the \Ecto.Adapters.SQL.query\, \Ecto.Adapters.SQL.query!\, and \Ecto.Adapters.SQL.stream\ functions. The new \Sobelow.SQL.Query\ and \Sobelow.SQL.Stream\ modules detect when these methods are called with non-parameterized or user-controlled SQL, allowing users to identify and mitigate these specific injection risks.

lib/sobelow/sql · high confidence

New XSS detection checks for content type, HTML, raw template values, and sendResp

Added four new submodules to the XSS vulnerability scanner to detect cross-site scripting risks in different contexts: \Sobelow.XSS.ContentType\ checks for unsafe content type headers in HTTP responses, \Sobelow.XSS.HTML\ identifies XSS in Phoenix controller \html\ calls, \Sobelow.XSS.Raw\ scans for unescaped user input in raw template rendering, and \Sobelow.XSS.SendResp\ detects XSS in \send\_resp\ body arguments. These new checks expand the tool's coverage of potential XSS vectors across the application's response handling and template rendering layers.

lib/sobelow/xss · high confidence

New directory traversal checks for File, send\_download, and send\_file

Added three new security checks for directory traversal vulnerabilities: File module functions (read, write, rm, mkdir, stream, etc.), the Phoenix Controller's send\_download function, and the send\_file function. Each new check identifies potential directory traversal risks in these specific code paths, with findings reported via the standard finding structure. Users can now detect traversal issues in file operations and HTTP response functions that were previously unmonitored.

lib/sobelow/traversal · high confidence

New security checks for CSP, CSRF, HSTS, headers, HTTPS, and secrets

Sobelow now includes dedicated checks for missing Content-Security-Policy headers, Cross-Site Request Forgery protections, HSTS, secure browser headers, HTTPS configuration, and hardcoded secrets. These new findings help identify common configuration vulnerabilities in Phoenix applications, with each check providing specific guidance on how to mitigate the identified risks.

lib/sobelow/config · high confidence

Project configuration and documentation overhaul

The project now includes a \.credo.exs\ file to configure the Credo static analysis tool, a \.formatter.exs\ file for Elixir code formatting, and a comprehensive \README.md\ that replaces the previous placeholder text with detailed usage instructions, CLI option documentation, and configuration file examples. Additionally, the IDE-specific \sobelow.iml\ file has been removed, and \.gitignore\ has been updated to exclude it.

(repo-wide) · high confidence

Security

Add vulnerability checks for Coherence, Ecto, and Plug

Sobelow now detects known vulnerabilities in the Coherence, Ecto, and Plug dependencies. Specifically, it flags Coherence versions ≤ 0.5.1 ([CVE redacted]), Ecto version 2.2.0 ([CVE redacted]), and several vulnerable versions of Plug ([CVE redacted], [CVE redacted], [CVE redacted]). Users should update these dependencies to resolve the reported security issues.

lib/sobelow/vuln · high confidence

Behavioural changes

Consolidated Sobelow CLI task into a single entry point

The \mix sobelow\ command now uses a single \Mix.Tasks.Sobelow\ module to handle all command-line options, replacing the previous two-file structure (\Mix.Tasks.Sobelow\ and \Mix.Tasks.Sobelow.Run\). This change simplifies the CLI interface by merging the task definition and execution logic, while preserving all existing flags (e.g., \--verbose\, \--root\, \--exit\) and deprecation warnings (e.g., \--with-code\ now redirects to \--verbose\).

lib/mix · high confidence

Major internal refactoring and expanded vulnerability detection capabilities

The core scanning engine has been significantly refactored to support a modular architecture with distinct checkers for SQL injection, command injection, cross-site scripting (XSS), and other vulnerability classes. The tool now supports multiple output formats including JSON, SARIF, and compact text, and allows results to be written to a file via the --out flag. Additionally, the scan process now includes a version check against a remote source and supports skipping specific vulnerabilities or files via configuration.

lib · high confidence

Removed obsolete configuration file

The file config/config.exs has been removed from the project. This file previously contained default configuration settings for the application, including environment-specific imports and dependency configurations. Users should ensure any required configuration is now handled through other means, such as environment variables or other configuration files.

config · high confidence

Test coverage

Add tests for command injection checks in os and System.cmd; Added CSRF test fixtures for router validation; Added and updated tests for formatting, logging, parsing, and SARIF output; Added test coverage for XSS vulnerabilities in content type, HTML, raw template, and send\_resp; Added test coverage for file traversal and send\_download vulnerabilities; Added test fixtures for Content Security Policy validation; Added test fixtures for Cross-Site Websocket Hijacking (CSWH) scenarios; Added test fixtures for configuration scenarios; Added test fixtures for secure headers; Added tests for CodeModule and EEx-based RCE detection; Added tests for DOS vulnerabilities in atom conversion functions; Added tests for SQL injection detection in query and stream functions; Added tests for security configuration checks; Added tests for the BinToTerm security check.

Dependencies

Upgrade to Elixir 1.7+ and modernize project configuration

The project now requires Elixir 1.7 or higher, enabling the use of modern Elixir syntax and features. The \mix.exs\ file has been significantly updated to include package metadata (licenses, maintainers, links), documentation settings, and aliases for development tasks. Additionally, the dependency list has been expanded to include \jason\ for JSON handling, while \ex\_doc\ and \credo\ are configured for development and testing environments.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 64 → 68 (+3.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 98 (+0.5)
  • Architecture 97 → 87 (-9.5)
  • Maturity 49 → 49 (+0.0)
  • Readiness 61 → 77 (+16.0)
  • Security 90 → 99 (+8.5)

Resolved (13)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (14 lines × 3) (lib/sobelow/vuln/coherence.ex)
  • Duplicated block (19 lines × 2) (lib/sobelow/config/hsts.ex)
  • Duplicated block (21 lines × 4) (lib/sobelow/config/csp.ex)
  • Duplicated block (7 lines × 2) (lib/sobelow/xss/raw.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • The README does not describe how to install Sobelow or where to find its binary after installation. (README.md)
  • TooManyMethods: Sobelow (lib/sobelow.ex)
  • dormant codebase — no living knowledge left to concentrate

New (21)

  • Dependency advisory scan runs only on code events
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (lib/sobelow/config/csrf.ex)
  • Duplicated block (19 lines × 3) (lib/sobelow/vuln/coherence.ex)
  • Duplicated block (21 lines × 4) (lib/sobelow/config/csp.ex)
  • Duplicated block (26 lines × 2) (lib/sobelow/config/hsts.ex)
  • Duplicated block (28 lines × 3) (lib/sobelow/config/csp.ex)
  • Duplicated block (5 lines × 2) (lib/sobelow/config/csrf.ex)
  • Duplicated block (5 lines × 9) (lib/sobelow/ci/os.ex)
  • Duplicated block (6 lines × 2) (lib/sobelow/xss/raw.ex)
  • Duplicated block (9 lines × 3) (lib/sobelow/vuln/cookie_rce.ex)
  • Duplicated block (9 lines × 6) (lib/sobelow/ci.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (lib/sobelow/config/csp.ex)
  • Outdated: credo
  • Outdated: ex_doc
  • Outdated: jason
  • …and 1 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

nccgroup/sobelow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b47ad2fbdda03894dfc4e72d635c52e9a6540832 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.