I'm interested in finding open-source tools for auditing some PHP code I didn't write, before putting it into production. I'll need black-box HTTP-probing scanners as well as static code parsers/analyzers.
Where can I find a good comprehensive list of all such tools, and a smaller list of which ones are actually worth trying?
Here's a start. I haven't tried any of them: