
gitxray
A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Maps GitHub organization relationships to identify lateral movement and privilege escalation paths via CI/CD pipelines and access controls, using…

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

GitHub Actions Pipeline Enumeration and Attack Tool

Scans filesystems and archives for Log4j libraries vulnerable to CVE-2021-44228 (Log4Shell) using PowerShell, aiding rapid incident response and…

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Automated scanner to detect compromised polyfill.io CDN scripts across mass URLs, with high-confidence alerts for untrusted domains and detailed…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Automated crawler that retrieves VEX (Vulnerability Exploitability eXchange) documents from package source repositories, validates them by PURL, and…

Web-based vulnerability fix tracker for Alpine Linux that ingests security databases and NVD feeds to monitor CVE fix status across packages.

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.