
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

A fast, simple, recursive content discovery tool written in Rust.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A coverage-guided REST API fuzzer developed on top of LibAFL

⚡️ Multiple target ZAP Scanning

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

A fast WordPress plugin enumeration tool


PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Node.js SDK for capturing and replaying API calls made to/from your service

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…