On the capability of static code analysis to detect security vulnerabilities | doi.page