21 repository-uri
Tools for identifying vulnerabilities in web applications and CMS platforms.
Explore 21 awesome GitHub repositories matching part of an awesome list · Web Application Scanning. Refine with filters or upvote what's useful.
XSStrike is an automated security scanning engine designed for web application discovery, input
Advanced XSS discovery and exploitation tool.
WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the
Specialized vulnerability scanner for WordPress sites.
Vulscan is a network service auditor and vulnerability scanner that utilizes the Nmap Scripting Engine to identify security flaws. It functions as a version-based flaw detector, matching detected software banners against an offline vulnerability database to identify potential security risks without requiring a constant internet connection. The tool provides mechanisms for refining identification accuracy, including an interactive mode for manual version overriding and configurable matching logic to filter results. It manages security data through a system for loading local datasets and synchr
Network and service-level vulnerability scanner.
A curated list of amazingly awesome Burp Extensions
Curated list of Burp Suite security extensions.
Detect and bypass web application firewalls and protection systems
Detects and bypasses web application firewalls.
CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs
Automated scanner for various CMS platforms.
HackBar plugin for Burpsuite
Browser-based tool for web penetration testing.
A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.
Vulnerability scanner for Drupal installations.
OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/
Vulnerability scanner for Joomla sites.
CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.
Scans WordPress, Joomla, and Drupal for vulnerabilities.
A Ruby framework designed to aid in the penetration testing of WordPress systems.
Comprehensive framework for WordPress exploitation.
Wordpress Attack Suite
Exploitation framework for WordPress targets.
GyoiThon is a growing penetration test tool using Machine Learning.
Automated web vulnerability scanner.
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
Detects Java deserialization vulnerabilities.
A simple Wordpress scanner written in python based on the work of WPScan (Ruby version), some features are inspired by WPSeku.
WordPress-specific vulnerability scanner.
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
Probes Java endpoints to identify serialized classes.
Automated network and web vulnerability scanner.