
argus-wp-watcher
WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

A collection of awesome resources related AI security

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

This is a defunct code base. The project is located at: https://github.com/WebGoat

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

OWASP Web Recon & Directory Discovery Platform

a Damn Vulnerable Serverless Application

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…