SAST

Static analysis reads your code without running it, so it can see every path and understands none of the context.

It knows the shape of a dangerous pattern and not whether that input is actually attacker-controlled, or whether something upstream already handled it. That is why the findings need a human: the tool is good at finding candidates and poor at deciding which are real, and a team that treats every result as a defect learns to ignore all of them.

Checked against the primary source.

More on Application security