
ssrf-king
SSRF plugin for burp Automates SSRF Detection in all of the Request

SSRF plugin for burp Automates SSRF Detection in all of the Request

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

WEB SERVICE SECURITY ASSESSMENT TOOL

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

A rapid HTTP downgrade smuggling scanner written in Go.

⚡️ Multiple target ZAP Scanning

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Rust-powered HTTP Request Smuggling Scanner.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

A Burp Extension designed to identify argument injection vulnerabilities.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.