
BWASP
BoB Web Application Security Project

BoB Web Application Security Project

Python-based GUI tool for automated detection of Cross-Site Scripting (XSS) vulnerabilities in web applications using payload injection and response…

Bash-based Google and Bing dorking tool for mass link harvesting, vulnerability analysis (SQLi, LFI), recon (subdomain, whois, nmap), and admin page…

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Automated XSS discovery tool with mass scanning, crawling, form detection, DOM analysis, and proxy/Tor support for web application security testing.

Multi-module web vulnerability scanner with directory enumeration, subdomain discovery, dork search, XSS/SQLi scanning, port scanning, WordPress…

Go-based web application fuzzer and scanner with template-driven requests, custom encoder/decoder support, and a JavaScript extension API for…

Multi-engine DAST scanner aggregating Nikto, ZAP, Nuclei, SkipFish, and Wapiti for automated web injection vulnerability detection with consolidated…

Multi-module web application scanner for vulnerability detection (XSS, SQLi, RCE), admin panel discovery, information gathering (port scan, whois,…

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

Automatic SQL injection and database takeover tool

A fast, simple, recursive content discovery tool written in Rust.

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

Automated web reconnaissance tool with dork scanning, SQLi/XSS detection, port scanning, admin panel discovery, and WAF/captcha bypass capabilities.

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for…