
URL_CHECKER
Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Rust-powered HTTP Request Smuggling Scanner.

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

A modern vulnerable web app

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

End to End testing of Web, API, Cloud, Events and Security

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

A Burp Extension designed to identify argument injection vulnerabilities.