


Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Automated Tool for Testing Header Based Blind SQL Injection

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

WordPress Sites Vulnerability Checker for CVE-2020-35489 - "Educational Use Only"

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Testing TLS/SSL encryption anywhere on any port

Download the entire Wayback Machine archive for a given URL.

Extract URLs, paths, secrets, and other interesting bits from JavaScript

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

detect technologies with wappalyzer alternative

CVE-2025-55182复现环境及RCE回显poc

A Go-based wrapper for the KNOXSS API to automate XSS vulnerability testing.

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…