
React2Shell-Scanner
Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Rust-powered HTTP Request Smuggling Scanner.

Vulnerability Assessment Scanner with Report Generation

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Burp Extension for collaboration in Faraday

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Automated testing suite with live traffic record and replay

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated Security Testing For REST API's

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…