
wafw00f
Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

A wrapper around grep, to help you grep for things

The Swiss Army knife for automated Web Application Testing

Differential testing framework for HTTP implementations

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

A static code analysis for WordPress (and PHP)

Documentation and reverse engineering of reCAPTCHA

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

GUI Burp Plugin to ease discovering of security holes in web applications

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

A collection of useful resources for hacking WordPress and it's plugins and themes

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Fuzzing Framework for Modules in Apache HTTPD Server

PoC CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0