
Vega
Open-source web application security scanner with automated vulnerability detection, proxy interception, and SSL/TLS testing for penetration testers…

Open-source web application security scanner with automated vulnerability detection, proxy interception, and SSL/TLS testing for penetration testers…

Open-source DAST proxy with agentic AI for intercepting, modifying, and replaying HTTP/HTTPS traffic. Automates web application security testing via…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Automated server vulnerability scanner integrated into CI/CD pipelines for security regression testing of web applications and cloud infrastructure.

CLI-driven security regression testing framework integrating OWASP ZAP and Selenium for automated web application penetration testing in CI/CD…

Automated web application security scanner integrated with OWASP ZAP for CI/CD pipelines. Performs vulnerability detection and security regression…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

The Swiss Army knife for automated Web Application Testing

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Web application firewall testing tool with 344+ attack payloads, auto WAF detection, bypass techniques, and full reconnaissance including DNS,…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Web app authorisation coverage scanning

CLI tool for automated detection of server-side and client-side template injection vulnerabilities across 44 template engines in 8 programming…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…