
GraphCrawler
GraphQL automated security testing toolkit

GraphQL automated security testing toolkit

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

The AI toolkit for building reliable browser automations

SSRF plugin for burp Automates SSRF Detection in all of the Request

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

API Scraper Agent for Web API's

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…


A next-generation crawling and spidering framework.

Ruby command-line interface to Burp Suite's REST API

Collaborative application security testing between humans and agents via CLI and MCP

Automatic SQL injection and database takeover tool