
Bug-Bounty-Arsenal-v.3
Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

The DevSecOps toolset for REST APIs

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Stage two containers

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

TLS checking component of purpleteam

Orchestration component of purpleteam

⚡️ Multiple target ZAP Scanning

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.