
pentest-mapper
A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

A wordlist of API names for web application assessments

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

a Damn Vulnerable Serverless Application

Burp Extension for collaboration in Faraday

Damn Vulnerable C# Application (API)

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…


Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Tests your WAF with +160 payloads


Collaborative application security testing between humans and agents via CLI and MCP

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…