
Scrapling
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

The ZAP Heads Up Display (HUD)

Automatically exported from code.google.com/p/jsunpack-n

Ruby In The Middle (HTTP/HTTPS interception proxy)

Cake Fuzzer is a project that is meant to help automatically and continuously discover vulnerabilities in web applications created based on specific…

client-side prototype pullution vulnerability scanner

Java Agent memory horse scanner combined with Call Graph modus

Proof-of-concept web app built on top of Frida

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

TypeScript Scenario-Based Web Application Fuzzing Framework

a systems programming language prioritizing verifiable correctness, determinism, and performance

Proof-of-concept web app built on top of Frida

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.

The Python Version of our Not Go-ing Anywhere Vulnerable Application

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…