
Bug-Bounty-Arsenal-v.3
Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

A lightweight caching proxy for package registries.

A reverse proxy like nginx, built on pingora, simple and efficient.

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

An egress firewall for untrusted workloads.

nginx 1.15.10 patch against cve-2021-23017 (ingress version)