graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.
The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations.
Legend
✅ – Enabled by Default
⚠️ – Disabled by Default
❌ – No Support
Implementation | Validations | Field Suggestions | Query Depth limit | Query Cost Analysis | Automatic Persisted Queries | Introspection | Debug Mode | Batch Requests |
---|---|---|---|---|---|---|---|---|
wp-graphql | 38 | ✅ | ⚠️ | ❌ | ❌ | ⚠️ | ⚠️ | ✅ |
graphql-php | 37 | ✅ | ⚠️ | ⚠️ | ❌ | ✅ | ⚠️ | ⚠️ |
Apollo | 34 | ✅ | ⚠️ | ⚠️ | ✅ | ✅ | ✅ | ✅ |
graphql-yoga | 34 | ✅ | ⚠️ | ❌ | ❌ | ⚠️ | ⚠️ | ⚠️ |
graphene | 34 | ✅ | ❌ | ❌ | ❌ | ✅ | ❌ | ⚠️ |
Ariadne | 34 | ✅ | ⚠️ | ⚠️ | ❌ | ✅ | ⚠️ | ❌ |
Strawberry | 34 | ✅ | ⚠️ | ❌ | ❌ | ✅ | ❌ | ❌ |
graphql-ruby | 28 | ✅ | ❌ | ⚠️ | ⚠️ | ✅ | ❌ | ✅ |
Sangria | 27 | ✅ | ⚠️ | ⚠️ | ❌ | ✅ | ❌ | ⚠️ |
Tartiflette | 26 | ❌ | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ |
graphql-java | 26 | ✅ | ⚠️ | ⚠️ | ❌ | ✅ | ❌ | ⚠️ |
gqlgen | 25 | ✅ | ❌ | ⚠️ | ⚠️ | ✅ | ⚠️ | ⚠️ |
Dgraph | 25 | ✅ | ❌ | ❌ | ⚠️ | ✅ | ❌ | ❌ |
graphql-go | 24 | ✅ | ❌ | ❌ | ❌ | ✅ | ⚠️ | ❌ |
juniper | 24 | ❌ | ❌ | ❌ | ❌ | ✅ | ❌ | ⚠️ |
Diana.jl | 10 | ✅ | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ |
gql-dart/gql | 9 | ✅ | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ |
Agoo | 1 | ❌ | ❌ | ❌ | ❌ | ✅ | ⚠️ | ❌ |
Use graphw00f to fingerprint a target GraphQL API and determine the backend implementation.
Overview WhatsMyName is a free, community-driven OSINT tool designed to identify where a username exists…
Managing disk usage is a crucial task for Linux users and administrators alike. Understanding which…
Efficient disk space management is vital in Linux, especially for system administrators who manage servers…
Knowing how to check directory sizes in Linux is essential for managing disk space and…
Managing user accounts is a core responsibility for any Linux administrator. Whether you’re securing a…
Linux offers powerful command-line tools for system administrators to view and manage user accounts. Knowing…