awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to wish-i-was/femida

Projects sharing features with Femida

30 open-source projects similar to wish-i-was/femida, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • nvisium/xssvalidatornVisium avatar

    nVisium/xssValidator

    420View on GitHub↗

    This is a burp intruder extender that is designed for automation and validation of XSS vulnerabilities.

    Java
    View on GitHub↗420
  • bitthebyte/bitblinderBitTheByte avatar

    BitTheByte/BitBlinder

    123View on GitHub↗

    BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities

    Python
    View on GitHub↗123
  • hahwul/dalfoxhahwul avatar

    hahwul/dalfox

    4,846View on GitHub↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    Gobugbountybugbounty-toolcicd-pipeline
    View on GitHub↗4,846
  • jiangsir404/xss-sql-fuzzjiangsir404 avatar

    jiangsir404/Xss-Sql-Fuzz

    63View on GitHub↗

    burpsuite 插件对GP所有参数(过滤特殊参数)一键自动添加xss sql payload 进行fuzz

    Python
    View on GitHub↗63
  • quitten/autorizeQuitten avatar

    Quitten/Autorize

    1,161View on GitHub↗

    Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests

    Python
    View on GitHub↗1,161

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • portswigger/reflected-parametersportswigger avatar

    portswigger/reflected-parameters

    24View on GitHub↗
    Java
    View on GitHub↗24
  • mystech7/burp-huntermystech7 avatar

    mystech7/Burp-Hunter

    152View on GitHub↗

    XSS Hunter Burp Plugin

    Java
    View on GitHub↗152
  • elkokc/reflectorelkokc avatar

    elkokc/reflector

    1,212View on GitHub↗

    Burp plugin able to find reflected XSS on page in real-time while browsing on site

    Java
    View on GitHub↗1,212
  • attackercan/burp-xss-sql-pluginattackercan avatar

    attackercan/burp-xss-sql-plugin

    44View on GitHub↗

    Publishing plugin which I used for years which helped me to find several bugbounty-worthy XSSes, OpenRedirects and SQLi.

    Python
    View on GitHub↗44
  • securityinnovation/authmatrixSecurityInnovation avatar

    SecurityInnovation/AuthMatrix

    647View on GitHub↗

    AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

    Python
    View on GitHub↗647
  • ultimatehackers/xsstrikeUltimateHackers avatar

    UltimateHackers/XSStrike

    15,027View on GitHub↗

    XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.

    Python
    View on GitHub↗15,027
  • reverse-shell/routersploitreverse-shell avatar

    reverse-shell/routersploit

    13,151View on GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    Python
    View on GitHub↗13,151
  • google/tsunami-security-scannergoogle avatar

    google/tsunami-security-scanner

    8,584View on GitHub↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Java
    View on GitHub↗8,584
  • bebiksior/evenbetterextensionsB

    bebiksior/EvenBetterExtensions

    0View on GitHub↗
    View on GitHub↗0
  • bebiksior/evenbetterB

    bebiksior/EvenBetter

    0View on GitHub↗
    View on GitHub↗0
  • aquasecurity/kube-hunteraquasecurity avatar

    aquasecurity/kube-hunter

    5,064View on GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Python
    View on GitHub↗5,064
  • bebiksior/caidoreflectorB

    bebiksior/CaidoReflector

    0View on GitHub↗
    View on GitHub↗0
  • coinbase/saluscoinbase avatar

    coinbase/salus

    29View on GitHub↗

    Salus: Guardian of Code Safety and Security

    HTML
    View on GitHub↗29
  • aquasecurity/kube-benchaquasecurity avatar

    aquasecurity/kube-bench

    8,078View on GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    View on GitHub↗8,078
  • aboul3la/sublist3raboul3la avatar

    aboul3la/Sublist3r

    10,957View on GitHub↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Python
    View on GitHub↗10,957
  • cak/reflectC

    cak/reflect

    0View on GitHub↗
    View on GitHub↗0
  • caido-community/notebookC

    caido-community/notebook

    0View on GitHub↗
    View on GitHub↗0
  • asaiken/dom-based-xss-finderAsaiKen avatar

    AsaiKen/dom-based-xss-finder

    76View on GitHub↗

    Chrome extension that finds DOM based XSS vulnerabilities

    JavaScript
    View on GitHub↗76
  • conanjun/xssblindinjectorconanjun avatar

    conanjun/xssblindinjector

    5View on GitHub↗

    burp插件,实现自动化xss盲打以及xss log

    Java
    View on GitHub↗5
  • coreyd97/burpcustomizerCoreyD97 avatar

    CoreyD97/BurpCustomizer

    586View on GitHub↗

    Because just a dark theme wasn't enough!

    Java
    View on GitHub↗586
  • coreyd97/stepperCoreyD97 avatar

    CoreyD97/Stepper

    202View on GitHub↗

    A natural evolution of Burp Suite's Repeater tool

    Java
    View on GitHub↗202
  • damian89/extended-xss-searchDamian89 avatar

    Damian89/extended-xss-search

    187View on GitHub↗

    A better version of my xssfinder tool - scans for different types of xss on a list of urls.

    Python
    View on GitHub↗187
  • danielmiessler/seclistsdanielmiessler avatar

    danielmiessler/SecLists

    71,596View on GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    PHP
    View on GitHub↗71,596
  • danmcinerney/pentest-machineD

    DanMcInerney/pentest-machine

    0View on GitHub↗
    View on GitHub↗0
  • bytebutcher/burp-send-tobytebutcher avatar

    bytebutcher/burp-send-to

    169View on GitHub↗

    Adds a customizable "Send to..."-context-menu to your BurpSuite.

    Java
    View on GitHub↗169