
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Web Application Security Scanner Framework

Web Application Vulnerability Scanner.

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

PwnXSS: Vulnerability (XSS) scanner exploit

Collaborative application security testing between humans and agents via CLI and MCP

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Extracts all possible endpoints, URLs, and paths from JavaScript files using customizable regex patterns for web application reconnaissance and API…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Web app authorisation coverage scanning

Proof-of-concept exploit demonstrating SSRF vulnerabilities in Firecrawl web scraper (CVE-2024-56800, CVE-2025-57818) with self-hosted setup and…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Next generation web scanner
