
GraphQLGrapper
Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Proof-of-concept exploit for CVE-2025-11771 demonstrating unauthenticated sale record creation via a WordPress REST API endpoint, with browser…

Exploit for CVE-2016-9177 targeting Spark Java web framework, demonstrating directory traversal vulnerability in version 2.5.1 for security testing…

Spring Cloud Gateway repository demonstrating CVE-2022-22947 exploitation for API security testing and vulnerability analysis.

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

GraphQL automated security testing toolkit

Python API security testing tool from OpenStack Security Group

An on-path blackbox network traffic security testing tool

Rust-powered HTTP Request Smuggling Scanner.

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.

Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management