
wpscan
WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Next generation web scanner

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for…

A modular vulnerability scanner with automatic report generation capabilities.

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

Modern tactical exploitation toolkit.

A fast DOM based XSS vulnerability scanner with simplicity.

Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14…

Web application vulnerability scanner

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

DOM XSS scanner for Single Page Applications

Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.

Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious…

XSS scanner that detects Cross-Site Scripting vulnerabilities in website by injecting malicious scripts

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.


Rust-powered HTTP Request Smuggling Scanner.