
open-source-llm-scanners
Curated list of open-source LLM security scanners and web app scanners, ordered by stars, for finding vulnerabilities in AI applications.

Curated list of open-source LLM security scanners and web app scanners, ordered by stars, for finding vulnerabilities in AI applications.

A fast tool to scan SAAS,PAAS App written in Go

SafeForge is an open-source mobile app hub built on GitLab that enables developers to build, upload, and share applications in a secure, AI-verified…

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Web app authorisation coverage scanning

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A collection of android security related resources

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

🦚 A web-app pentesting suite written in rust .

CVE-2025-55182 React Server Components Remote Code Execution Exploit Tool

Web-based project management interface for penetration testing and bug bounty workflows, automating port scanning with Nmap/Masscan and subdomain…

A doggo that helps look for security issues in your repositories.

Locally-hosted, air-gapped VAPT platform that runs 8 parallel scanning modules, deterministically scores findings with CVSS v3.1, and generates PDF…

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)