
tplmap
Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Automated testing suite with live traffic record and replay

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Executable security regression testing for agentic applications and MCP-integrated systems.

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

MCP server for Slither static analysis of Solidity smart contracts

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…