
nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

PHP Static Analysis Tool - discover bugs in your code without running it!

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Main repo for hosting release binaries

OpenSSF Scorecard - Security health metrics for Open Source

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

Fast and accurate AI powered file content types detection

A static analyzer for Java, C, C++, and Objective-C

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

0-day malware detection for binaries, source & scripts (that doesn't suck)

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…