
pwnproxy
An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

An egress firewall for untrusted workloads.

Rust-powered HTTP Request Smuggling Scanner.

Vulnerability Assessment Scanner with Report Generation

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Executable security regression testing for agentic applications and MCP-integrated systems.

Burp Extension for collaboration in Faraday

OPNsense GUI, API and systems backend

nginx 1.15.10 patch against cve-2021-23017 (ingress version)

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

A lightweight caching proxy for package registries.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…