
Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Bandit is a tool designed to find common security issues in Python code.

A static code analysis for WordPress (and PHP)

client-side prototype pullution vulnerability scanner

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

A security scanner for your LLM agentic workflows

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

PHP Static Analysis Tool - discover bugs in your code without running it!

Easy setup of static analysis tools for Android and Java projects.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

nodejsscan is a static security code scanner for Node.js applications.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

A static analyzer for Java, C, C++, and Objective-C

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

C++ python bytecode disassembler and decompiler