
burpcommander
Ruby command-line interface to Burp Suite's REST API

Ruby command-line interface to Burp Suite's REST API

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

Http request smuggling vulnerability scanner