Most of the scanning rules from the researchers manually written for the vulnerability, but also some of the following from the open source system. Cobra scanning rules are compatible with most open source systems.

SonarQube

RIPS

GrepBugs