
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…


Documentation and reverse engineering of reCAPTCHA

The Swiss Army knife for automated Web Application Testing

Fuzzing Framework for Modules in Apache HTTPD Server

Differential testing framework for HTTP implementations

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Next generation web scanner

A collection of useful resources for hacking WordPress and it's plugins and themes

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…


A wrapper around grep, to help you grep for things