awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to fuzzapi/fuzzapi

Open-source alternatives to Fuzzapi

30 open-source projects similar to fuzzapi/fuzzapi, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Fuzzapi alternative.

  • ffuf/ffufالصورة الرمزية لـ ffuf

    ffuf/ffuf

    15,618عرض على GitHub↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    Gofuzzerinfosecpentesting
    عرض على GitHub↗15,618
  • alufers/mitmproxy2swaggerالصورة الرمزية لـ alufers

    alufers/mitmproxy2swagger

    9,530عرض على GitHub↗

    mitmproxy2swagger is a tool that transforms captured mitmproxy network traffic into structured OpenAPI schemas for reverse-engineering REST APIs. It functions as an OpenAPI schema converter and network traffic documentation utility, extracting API endpoints and data structures from captured network packets to create formal technical references. The tool enables the reconstruction of undocumented APIs by converting intercepted HTTP request and response patterns into specifications. It supports merging multiple traffic capture files into a single schema to incrementally expand an API map and ut

    HTMLmitmproxyopenapireverse-engineering
    عرض على GitHub↗9,530
  • ameenmaali/qsfuzzالصورة الرمزية لـ ameenmaali

    ameenmaali/qsfuzz

    300عرض على GitHub↗

    qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.

    Go
    عرض على GitHub↗300
  • api-security/apikitالصورة الرمزية لـ API-Security

    API-Security/APIKit

    2,270عرض على GitHub↗

    APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

    Java
    عرض على GitHub↗2,270

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Find more with AI search
  • apiclarity/apiclarityالصورة الرمزية لـ apiclarity

    apiclarity/apiclarity

    572عرض على GitHub↗

    An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and identify API security risks.

    Go
    عرض على GitHub↗572
  • assetnote/kiterunnerالصورة الرمزية لـ assetnote

    assetnote/kiterunner

    3,204عرض على GitHub↗

    Contextual Content Discovery Tool

    Go
    عرض على GitHub↗3,204
  • blst-security/cherrybombالصورة الرمزية لـ blst-security

    blst-security/cherrybomb

    1,231عرض على GitHub↗

    Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

    Rust
    عرض على GitHub↗1,231
  • bo0om/fuzz.txtالصورة الرمزية لـ Bo0oM

    Bo0oM/fuzz.txt

    3,312عرض على GitHub↗

    Potentially dangerous files

    عرض على GitHub↗3,312
  • centralmind/gatewayالصورة الرمزية لـ centralmind

    centralmind/gateway

    530عرض على GitHub↗

    Universal MCP-Server for your Databases optimized for LLMs and AI-Agents.

    Go
    عرض على GitHub↗530
  • d4rckh/vafالصورة الرمزية لـ d4rckh

    d4rckh/vaf

    318عرض على GitHub↗

    Vaf is a cross-platform very advanced and fast web fuzzer written in nim

    Nim
    عرض على GitHub↗318
  • dvyukov/go-fuzzالصورة الرمزية لـ dvyukov

    dvyukov/go-fuzz

    4,853عرض على GitHub↗

    go-fuzz is a coverage-guided randomized testing tool for identifying crashes and logic bugs in Go code. It consists of a fuzzer that evolves random inputs based on code execution paths, an instrumentation tool that produces binaries for tracking coverage, and a seed corpus manager. The tool utilizes compile-time binary instrumentation to monitor branch coverage and employs a feedback-driven mutation loop to prioritize inputs that reach new sections of the codebase. It includes capabilities for comparative differential testing to identify logic errors by executing different implementations of

    Go
    عرض على GitHub↗4,853
  • dwisiswant0/wadl-dumperالصورة الرمزية لـ dwisiswant0

    dwisiswant0/wadl-dumper

    98عرض على GitHub↗

    Dump all available paths and/or endpoints on WADL file.

    Go
    عرض على GitHub↗98
  • endava/catsالصورة الرمزية لـ Endava

    Endava/cats

    1,359عرض على GitHub↗

    CATS is a REST API Fuzzer and negative testing tool for OpenAPI endpoints. CATS automatically generates, runs and reports tests with minimum configuration and no coding effort. Tests are self-healing and do not require maintenance.

    Java
    عرض على GitHub↗1,359
  • flipkart-incubator/astraالصورة الرمزية لـ flipkart-incubator

    flipkart-incubator/Astra

    2,639عرض على GitHub↗

    Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints

    Pythonci-cdowasppenetration-testing
    عرض على GitHub↗2,639
  • fuzzdb-project/fuzzdbالصورة الرمزية لـ fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819عرض على GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    عرض على GitHub↗8,819
  • googleprojectzero/fuzzilliالصورة الرمزية لـ googleprojectzero

    googleprojectzero/fuzzilli

    2,214عرض على GitHub↗

    A JavaScript Engine Fuzzer

    Swift
    عرض على GitHub↗2,214
  • imperva/automatic-api-attack-toolالصورة الرمزية لـ imperva

    imperva/automatic-api-attack-tool

    495عرض على GitHub↗

    Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

    Java
    عرض على GitHub↗495
  • kisspeter/apifuzzerالصورة الرمزية لـ KissPeter

    KissPeter/APIFuzzer

    467عرض على GitHub↗

    Fuzz test your application using your OpenAPI or Swagger API definition without coding

    Python
    عرض على GitHub↗467
  • metlo-labs/metloالصورة الرمزية لـ metlo-labs

    metlo-labs/metlo

    1,777عرض على GitHub↗

    Metlo is an open-source API security platform.

    TypeScript
    عرض على GitHub↗1,777
  • microsoft/restler-fuzzerالصورة الرمزية لـ microsoft

    microsoft/restler-fuzzer

    2,915عرض على GitHub↗

    RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.

    Python
    عرض على GitHub↗2,915
  • opticdev/opticالصورة الرمزية لـ opticdev

    opticdev/optic

    1,534عرض على GitHub↗

    OpenAPI linting, diffing and testing. Optic helps prevent breaking changes, publish accurate documentation and improve the design of your APIs.

    TypeScript
    عرض على GitHub↗1,534
  • owasp/offatالصورة الرمزية لـ OWASP

    OWASP/OFFAT

    660عرض على GitHub↗

    The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.

    Python
    عرض على GitHub↗660
  • rhinosecuritylabs/swagger-ezالصورة الرمزية لـ RhinoSecurityLabs

    RhinoSecurityLabs/Swagger-EZ

    188عرض على GitHub↗

    A tool geared towards pentesting APIs using OpenAPI definitions.

    JavaScript
    عرض على GitHub↗188
  • rub-nds/rest-attackerالصورة الرمزية لـ RUB-NDS

    RUB-NDS/REST-Attacker

    80عرض على GitHub↗

    REST-Attacker is designed as a proof-of-concept for the feasibility of testing generic real-world REST implementations. Its goal is to provide a framework for REST security research.

    Python
    عرض على GitHub↗80
  • s0md3v/arjunالصورة الرمزية لـ s0md3v

    s0md3v/Arjun

    6,086عرض على GitHub↗

    Arjun is an HTTP parameter discovery tool that identifies valid parameters on web endpoints by testing large dictionaries of parameter names against target URLs. It systematically probes endpoints using GET, POST, JSON, and XML request formats to find which parameters the server accepts, and can detect parameters whose values appear reflected in the response body. The tool distinguishes itself through its multi-method scanning approach, passive parameter collection from public archives like OTX and CommonCrawl, and its ability to detect value-sensitive parameters that only trigger a response

    Pythonapi-fuzzerapi-fuzzingapi-testing
    عرض على GitHub↗6,086
  • teebytes/tnt-fuzzerالصورة الرمزية لـ Teebytes

    Teebytes/TnT-Fuzzer

    110عرض على GitHub↗

    OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.

    Python
    عرض على GitHub↗110
  • tno-s3/wuppiefuzzالصورة الرمزية لـ TNO-S3

    TNO-S3/WuppieFuzz

    209عرض على GitHub↗

    A coverage-guided REST API fuzzer developed on top of LibAFL

    Rust
    عرض على GitHub↗209
  • wallarm/gotestwafالصورة الرمزية لـ wallarm

    wallarm/gotestwaf

    1,789عرض على GitHub↗

    An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

    Go
    عرض على GitHub↗1,789
  • xmendez/wfuzzالصورة الرمزية لـ xmendez

    xmendez/wfuzz

    6,519عرض على GitHub↗

    Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism

    Python
    عرض على GitHub↗6,519
  • akto-api-security/aktoالصورة الرمزية لـ akto-api-security

    akto-api-security/akto

    1,486عرض على GitHub↗

    Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure

    Java
    عرض على GitHub↗1,486