
katana
A next-generation crawling and spidering framework.

A next-generation crawling and spidering framework.

A modular vulnerability scanner with automatic report generation capabilities.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…


Community curated list of templates for the nuclei engine to find security vulnerabilities.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web…

Automatic SQL injection and database takeover tool

A fast, simple, recursive content discovery tool written in Rust.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Rust-powered HTTP Request Smuggling Scanner.