
gotestwaf
An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

SSRF plugin for burp Automates SSRF Detection in all of the Request

Hidden parameters discovery suite

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

Executable security regression testing for agentic applications and MCP-integrated systems.

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

find sensitive data leaking from ServiceNow instances.

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

OAuth Request Crafter

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object…

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption