
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

Next generation web scanner

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Application scanning component of purpleteam

OWASP Web Recon & Directory Discovery Platform

BoB Web Application Security Project

Rust-powered HTTP Request Smuggling Scanner.

Ruby command-line interface to Burp Suite's REST API