
dynast-bench
A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

A coverage-guided REST API fuzzer developed on top of LibAFL

A fast WordPress plugin enumeration tool

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Node.js SDK for capturing and replaying API calls made to/from your service

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.


Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

⚡️ Multiple target ZAP Scanning

A fast, simple, recursive content discovery tool written in Rust.

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.