A list of open source web security scanners on GitHub and GitLab, ordered by Stars. It does not provide in-depth analysis – for more analysis or a wider range of tools, see the links below.
Note that some large projects have multiple repos – in which case the second most relevant repo is included immediately after and is indented.
Tools which can find a range of ‘unknown’ vulnerabilities on any websites.
Main Site | Last Commit | Committers | Stars |
---|---|---|---|
ZAP | |||
– ZAP Extensions | |||
Hetty | |||
W3af | |||
Arachni | |||
Astra | |||
Wapiti | |||
Skipfish | |||
Sitadel | |||
Taipan | |||
Vega | |||
Reaper | |||
BrowserBruter | |||
Tuplar | |||
Ugly-duckling | |||
Jawfish | |||
Pākiki | |||
Browserker |
For more information click here.
Playwright-MCP (Model Context Protocol) is a cutting-edge tool designed to bridge the gap between AI…
JBDev is a specialized development tool designed to streamline the creation and debugging of jailbreak…
The Kereva LLM Code Scanner is an innovative static analysis tool tailored for Python applications…
Nuclei-Templates-Labs is a dynamic and comprehensive repository designed for security researchers, learners, and organizations to…
SSH-Stealer and RunAs-Stealer are malicious tools designed to stealthily harvest SSH credentials, enabling attackers to…
Control flow flattening is a common obfuscation technique used by OLLVM (Obfuscator-LLVM) to transform executable…