
generator-burp-extension
Yeoman generator that scaffolds Burp Suite extension projects with customizable features like custom tabs, context menus, HTTP listeners, and scanner…

Yeoman generator that scaffolds Burp Suite extension projects with customizable features like custom tabs, context menus, HTTP listeners, and scanner…

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…

Collection of Bambda scripts for Burp Suite enabling custom table filters, columns, Repeater actions, match-and-replace rules, and scan checks to…

Open-source DAST proxy with agentic AI for intercepting, modifying, and replaying HTTP/HTTPS traffic. Automates web application security testing via…

CLI tool for automating HTTP request routing through Burp Suite proxy to load reconnaissance URLs and streamline web application security testing…

Go-based web application fuzzer and scanner with template-driven requests, custom encoder/decoder support, and a JavaScript extension API for…

Automated reconnaissance tool that performs subdomain enumeration, vulnerability scanning, OSINT, port scanning, and web analysis to map attack…

PHP framework for building web applications and console tools with reusable components, security best practices, and a large ecosystem of bundles.

Lightweight micro-framework for running security tools on OpenWrt routers and SBCs. Features WiFi management, extensible module system, integrated…

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

AI-powered web scraping and data extraction library that extracts structured information from any webpage using natural language instructions, with…

Attack surface discovery and AI-assisted triage for security researchers. Endpoint & parameter mapping with actionable testing hints.

Automated scanner to detect compromised polyfill.io CDN scripts across mass URLs, with high-confidence alerts for untrusted domains and detailed…

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

Automated detection and tracking of fake engagement on GitHub — daily CI, zero infrastructure