
BWASP
BoB Web Application Security Project

BoB Web Application Security Project

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Rust-powered HTTP Request Smuggling Scanner.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

Next generation web scanner

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

A Burp Extension designed to identify argument injection vulnerabilities.

Ruby command-line interface to Burp Suite's REST API

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Http request smuggling vulnerability scanner