
Http11Probe
An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

Security checks for your researches

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Inspect all of your Heroku apps for vulnerable versions of the JSON gem

One command grades your whole cloud account — misconfigurations, missing observability, and security posture.

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

a plugin that protects your wp site from the CVE-2017-8295 vulnerability

Scan your NGINX configuration to determine whether it is affected by CVE-2026-42945.

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Script to make changes on registry to fix CVE-2013-3900. It comes with an option to undo in case it breaks something on your environment.

kubeaudit helps you audit your Kubernetes clusters against common security controls

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…