Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pphack — Advanced Client-Side Prototype Pollution Scanner | Kitploit
Tools/GitHubGitHub/edoardottt/pphack
Vulnerability ScannersWeb Application ExploitationWeb SecurityPenetration Testing
GitHubedoardottt/pphack

pphack

Advanced Client-Side Prototype Pollution Scanner

View Repository
2502610 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

pphack

Advanced Client-Side Prototype Pollution Scanner

Coded with 💙 by edoardottt

go action go report card
Share on Twitter!

Install • Get Started • Examples • Changelog • Contributing • License

Install 📡

Using Go

root@kitploit:~
go install github.com/edoardottt/pphack/cmd/pphack@latest

pphack relies on chromedp, so you need Chrome or Chromium-based browser.

Get Started 🎉

root@kitploit:~
Usage:
  pphack [flags]

Flags:
INPUT:
   -u, -url string   Input URL
   -l, -list string  File containing input URLs

CONFIGURATION:
   -c, -concurrency int       Concurrency level (default 50)
   -t, -timeout int           Connection timeout in seconds (default 20)
   -px, -proxy string         Set a proxy server (URL)
   -rl, -rate-limit int       Set a rate limit (per second)
   -ua, -user-agent string    Set a custom User Agent (random by default)
   -H, -headers string[]      Set custom headers
   -Hf, -headers-file string  File containing custom headers

SCAN:
   -p, -payload string            Custom payload
   -js, -javascript string        Run custom Javascript on target
   -jsf, -javascript-file string  File containing custom Javascript to run on target
   -e, -exploit                   Automatic Exploitation

OUTPUT:
   -o, -output string  File to write output results
   -v, -verbose        Verbose output
   -s, -silent         Silent output. Print only results
   -j, -json           JSON output

Examples 💡

Scan a single URL

root@kitploit:~
pphack -u https://edoardottt.github.io/pphack-test/
root@kitploit:~
echo https://edoardottt.github.io/pphack-test/ | pphack

Scan a list of URLs

root@kitploit:~
pphack -l targets.txt
root@kitploit:~
cat targets.txt | pphack

Automatic exploitation

root@kitploit:~
pphack -e -u https://edoardottt.github.io/pphack-test/

Read the Wiki to understand how to use pphack.

Changelog 📌

Detailed changes for each release are documented in the release notes.

Contributing 🛠

Just open an issue / pull request.

Before opening a pull request, download golangci-lint and run

root@kitploit:~
golangci-lint run

If there aren't errors, go ahead :)

In the news 📰

  • tl;dr sec Newsletter

License 📝

This repository is under MIT License.
edoardottt.com to contact me.

Download Tool