Vulnerabilities and scanning

AST analysis

AST analysis parses source code into an Abstract Syntax Tree and queries the tree for vulnerable patterns. Because it works on the structure of the language rather than raw text, it can distinguish a string literal containing 'eval' from an actual call to the eval function. It is one of the techniques static analysis (SAST) tools use.