From last few day , I was searching for static code analysis tool for ColdFusion. I have not got a good one till now. I found two.
From YASCA I was getting only XSS alerts and some alerts for session mgmt, nothing more than that. I have tried with my entire project. I am not even able to properly install cf-metrics using ColdFusion10 , After putting the required jar file in the lib folder I was not able to access any one my IIS site because of some isapi redirect isse.
Any other tools available?