Static analysis
Checking software by reading its code rather than running it.
A static check reads files and looks for patterns: a credential-shaped string, a call that starts a process, a sentence in a tool description that addresses the model. It never executes anything, which makes it safe to point at software nobody trusts yet.
Its limits are the mirror of that. It sees what is written down, not what happens: code built at run time, minified bundles and compiled binaries hide from it, and a pattern that matches is a reason to look, not proof of a fault.
Every automated check on this site is static, because running an unknown package to find out whether it is malicious is the same act as being attacked by it.
Reading a clean static result as a clean bill. It means nothing matched in what could be read, and how much could be read is the number to ask for.
Related terms
See Static analysis on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue