How to implement RIPS code analyser in your php script

| Last Updated: | In: Core php

RIPS is a static code analysis tool to automatically scan vulnerabilities for your PHP applications. Johannes Dahse the developer of RIPS is released the initial version in May 2010 as open source software. Besides the structured output of found vulnerabilities RIPS also offers an integrated code audit framework for further manual analysis.

Static code analysis attempt to highlight possible vulnerabilities from your static PHP source code by using techniques such as traint analysis and data flow analysis. Ideally, such tools would automatically find security loop flaws-with high degree of confidence, this is beyond the art for many types of application security flaws.

Bellow critical security vulnerabilities were detected by RIPS

The critical security vulnerabilities which were detected by RIPS during static code analysis are Remote Code Execution, SQL Injection, Cross-Site Scripting, Remote Code Execution, Local File Inclusion, PHP Object Injection and etc..

RIPS Requirements

  • Web server: Apache or Nginx recommended
  • PHP: latest version recommended
  • browser: Firefox recommended

RIPS Supports Vulnerability Types

The detection of the following vulnerability types is supported:

  • Code Execution
  • Command Execution
  • Connection String Injection
  • Cross-Site Scripting
  • HTTP Response Splitting
  • File Disclosure
  • File Inclusion
  • File Manipulation
  • LDAP Injection
  • PHP Object Injection
  • SQL Injection
  • XPath Injection

Download + Install Setup

  • Download the latest release Of RIPS from Github.
  • Extract the files to your local server root directory and make sure your web server has file permissions.
  • Open your browser at http://localhost/rips/ and follow the instructions on the main page.

See screenshot below






Tags: , , ,

About: Prem Tiwari

Prem Tiwari is the founder of and is a professional developer who has vast experience in PHP and open source technologies. Apart from this, he is a blogger by hobby.

You may also like:

Follow us!

Get Free Access of 380+ Scripts

Don't worry you'll not be spammed!

Featured eBook

WordPress Security Guide

Free Guide: Learn how to implement security guideline in your WordPress site...


Pincode Finder

pincode-finder tool

Online Pincode Finder

Best tool to locate post Office address and pincodes of all india...

Copyright © 2013-2017