
DependencyCheck
The dependency-check repository has moved:

The dependency-check repository has moved:

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

⚡️ Multiple target ZAP Scanning

Rust-powered HTTP Request Smuggling Scanner.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Automated testing suite with live traffic record and replay

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Vulnerability Assessment Scanner with Report Generation

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Burp Extension for collaboration in Faraday

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.