
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

The Swiss Army knife for automated Web Application Testing

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Next generation web scanner


TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

GUI Burp Plugin to ease discovering of security holes in web applications

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…


A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Differential testing framework for HTTP implementations

LLM powered fuzzing via OSS-Fuzz.

Automatic SSTI detection tool with interactive interface

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR