npx vchk
Paste code and hit Scan to find vulnerabilities
Detects SQL injection, hardcoded secrets, XSS, weak crypto, and more