
waf-bypass
Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…

A fast WordPress plugin enumeration tool

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Automated HTTP Request Repeating With Burp Suite

A wordlist of API names for web application assessments

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

Tests your WAF with +160 payloads

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

An intentionally designed broken web application based on REST API.

SSRF plugin for burp Automates SSRF Detection in all of the Request


Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

CVE-2026-9830 Proof of Concept

Open-source MITM proxy to intercept, inspect, and mock network traffic.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

SAML2 Burp Extension