
toolbox
Collaborative application security testing between humans and agents via CLI and MCP

Collaborative application security testing between humans and agents via CLI and MCP

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

A fast WordPress plugin enumeration tool

The AI toolkit for building reliable browser automations

Web vulnerability scanner written in Python3

OWASP D4N155 - Intelligent and dynamic wordlist using OSINT

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Next generation web scanner

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

API Scraper Agent for Web API's

Web app authorisation coverage scanning