


VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

IoTGoat is a deliberately insecure firmware based on OpenWrt.

An installable desktop variant of OWASP Threat Dragon

OWASP D4N155 - Intelligent and dynamic wordlist using OSINT

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

⚡️ Multiple target ZAP Scanning

The DevSecOps toolset for REST APIs

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

Hidden parameters discovery suite

🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations