
RatRace
A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

The collaborative web app pentest suite

A rapid HTTP downgrade smuggling scanner written in Go.

Go client to communicate with Chaos DB API.

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Burp Commander written in Go

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Discover hidden parameters in Caido

Zap Extension for collaboration in Faraday

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…