awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to h3xstream/burp-retire-js

Projects sharing features with Burp Retire Js

30 open-source projects similar to h3xstream/burp-retire-js, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • doyensec/inqldoyensec avatar

    doyensec/inql

    1,782View on GitHub↗

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    Kotlin
    View on GitHub↗1,782
  • portswigger/backslash-powered-scannerPortSwigger avatar

    PortSwigger/backslash-powered-scanner

    712View on GitHub↗

    Finds unknown classes of injection vulnerabilities

    Java
    View on GitHub↗712
  • arachni/arachniArachni avatar

    Arachni/arachni

    4,000View on GitHub↗

    Arachni is a dynamic application security testing vulnerability scanner and web application security tool. It functions as a distributed web audit framework that performs active and passive audits to identify security flaws such as SQL injection and cross-site scripting. The project features a JavaScript-aware web crawler that executes scripts and monitors DOM changes to analyze modern dynamic web applications. It utilizes server platform fingerprinting to target compatible security payloads and provides a grid-based system to distribute scanning workloads across multiple nodes. The tool cov

    Rubyanalysisarachniaudit
    View on GitHub↗4,000
  • gosecure/csp-auditorGoSecure avatar

    GoSecure/csp-auditor

    142View on GitHub↗

    Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

    Java
    View on GitHub↗142

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • trufflesecurity/trufflehogtrufflesecurity avatar

    trufflesecurity/trufflehog

    24,630View on GitHub↗

    Trufflehog is a security tool designed to continuously monitor code repositories and cloud environments to detect, verify, and remediate exposed sensitive credentials and API keys. It functions as a comprehensive secret scanning engine that integrates directly into deployment pipelines and version control systems to intercept sensitive data before it is committed or pushed. By utilizing read-only operations and volatile memory processing, the system ensures that discovered credentials are never stored persistently, maintaining strict data privacy throughout the scanning lifecycle. The platfor

    Gocredentialsdevsecopsdynamic-analysis
    View on GitHub↗24,630
  • portswigger/collaborator-everywherePortSwigger avatar

    PortSwigger/collaborator-everywhere

    447View on GitHub↗

    A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator

    Java
    View on GitHub↗447
  • linkedin/sometimelinkedin avatar

    linkedin/sometime

    60View on GitHub↗

    A BurpSuite plugin to detect Same Origin Method Execution vulnerabilities

    Java
    View on GitHub↗60
  • sullo/niktosullo avatar

    sullo/nikto

    10,104View on GitHub↗

    Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are

    Perl
    View on GitHub↗10,104
  • portswigger/http-request-smugglerportswigger avatar

    portswigger/http-request-smuggler

    1,213View on GitHub↗

    This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…

    Java
    View on GitHub↗1,213
  • secdec/attack-surface-detector-burpsecdec avatar

    secdec/attack-surface-detector-burp

    113View on GitHub↗

    The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters

    Java
    View on GitHub↗113
  • vulnerscom/burp-vulners-scannervulnersCom avatar

    vulnersCom/burp-vulners-scanner

    897View on GitHub↗

    Vulnerability scanner based on vulners.com search API

    Java
    View on GitHub↗897
  • voulnet/desharializeV

    Voulnet/desharialize

    0View on GitHub↗
    View on GitHub↗0
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • portswigger/httpoxy-scannerPortSwigger avatar

    PortSwigger/httpoxy-scanner

    95View on GitHub↗

    A Burp Suite extension that checks for the HTTPoxy vulnerability.

    Java
    View on GitHub↗95
  • federicodotta/java-deserialization-scannerfedericodotta avatar

    federicodotta/Java-Deserialization-Scanner

    802View on GitHub↗

    All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

    Java
    View on GitHub↗802
  • reverse-shell/routersploitreverse-shell avatar

    reverse-shell/routersploit

    13,151View on GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    Python
    View on GitHub↗13,151
  • joaomatosf/jexbossjoaomatosf avatar

    joaomatosf/jexboss

    2,512View on GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    View on GitHub↗2,512
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    View on GitHub↗9,144
  • anshumanpattnaik/http-request-smugglinganshumanpattnaik avatar

    anshumanpattnaik/http-request-smuggling

    539View on GitHub↗

    HTTP Request Smuggling Detection Tool

    Python
    View on GitHub↗539
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
  • 1337g/cve-2017-102711

    1337g/CVE-2017-10271

    0View on GitHub↗
    View on GitHub↗0
  • alexcowperthwaite/passkeyscanneralexcowperthwaite avatar

    alexcowperthwaite/PasskeyScanner

    3View on GitHub↗
    Java
    View on GitHub↗3
  • augustd/burp-suite-error-message-checksaugustd avatar

    augustd/burp-suite-error-message-checks

    65View on GitHub↗

    Burp Suite extension to passively scan for applications revealing server error messages

    Java
    View on GitHub↗65
  • assetnote/h2csmugglerA

    assetnote/h2csmuggler

    0View on GitHub↗
    View on GitHub↗0
  • augustd/burp-suite-gwt-scanaugustd avatar

    augustd/burp-suite-gwt-scan

    13View on GitHub↗

    Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests

    Java
    View on GitHub↗13
  • augustd/burp-suite-software-version-checksaugustd avatar

    augustd/burp-suite-software-version-checks

    33View on GitHub↗

    Burp extension to passively scan for applications revealing software version numbers

    Java
    View on GitHub↗33
  • auth0/repo-supervisorauth0 avatar

    auth0/repo-supervisor

    653View on GitHub↗

    Scan your code for security misconfiguration, search for passwords and secrets. :mag:

    JavaScript
    View on GitHub↗653
  • baidu/openraspbaidu avatar

    baidu/openrasp

    2,964View on GitHub↗

    🔥Open source RASP solution

    C++
    View on GitHub↗2,964
  • bb00/zer0dumpB

    bb00/zer0dump

    0View on GitHub↗
    View on GitHub↗0
  • albinowax/activescanplusplusalbinowax avatar

    albinowax/ActiveScanPlusPlus

    661View on GitHub↗

    ActiveScan++ Burp Suite Plugin

    Java
    View on GitHub↗661