Applying any additional form of static analysis will find new bugs. Writing a new fuzzer is equally effective! https://googleprojectzero.blogspot.co.uk/2017/09/the-great-dom-fuzz-off-of-2017.html?m=1