
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Node.js SDK for capturing and replaying API calls made to/from your service

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

⚡️ Multiple target ZAP Scanning

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…


A fast, simple, recursive content discovery tool written in Rust.

A fast WordPress plugin enumeration tool

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…