
jaeles
The Swiss Army knife for automated Web Application Testing

The Swiss Army knife for automated Web Application Testing

Next generation web scanner


WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…


XSS spider - 66/66 wavsep XSS detected

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

A wrapper around grep, to help you grep for things

A collection of useful resources for hacking WordPress and it's plugins and themes

Documentation and reverse engineering of reCAPTCHA

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

GUI Burp Plugin to ease discovering of security holes in web applications

Fuzzing Framework for Modules in Apache HTTPD Server