
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool


Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

A next-generation crawling and spidering framework.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Web vulnerability scanner written in Python3

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Fast and easy-to-use directory brute-forcer written in Go.

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…