A modern, console-based web penetration testing toolkit with a TUI. Features an HTTP/HTTPS proxy, active/passive vulnerability scanner, Repeater, Intruder, Spider, and more. Free & open-source.
-
Updated
Aug 31, 2026 - Python
A modern, console-based web penetration testing toolkit with a TUI. Features an HTTP/HTTPS proxy, active/passive vulnerability scanner, Repeater, Intruder, Spider, and more. Free & open-source.
A Flask-based phishing detection platform for analyzing URLs, emails, and SMS messages using a rule-based risk assessment engine.
A lightweight Python web reconnaissance tool designed to brute-force and discover hidden files, directories, and configuration leaks on web servers using automated HTTP request routing and status code auditing
aplikasi manajemen keamanan web berbasis PHP modular berkinerja tinggi yang dirancang untuk melindungi aplikasi web dari berbagai ancaman siber (seperti SQL Injection, XSS, RCE, LFI/RFI)
Write-ups from PortSwigger Web Security Academy labs: SQL Injection, XSS, and more as I progress
Burp Suite extension for HTTP verb tampering testing using Montoya API.
URLUNIQ 2.0 is an advanced offline URL normalization, canonicalization, deduplication, classification, filtering, analysis, and reporting toolkit built for security researchers, bug bounty hunters, and large URL datasets.
An automated SQL injection testing to uncover backend database vulnerabilities
Amba2Pen is a Python-based tool designed to streamline the penetration testing process by automating various pentest tasks.
Air-gapped LLM-assisted web application pentest triage — Burp Suite extension + local Ollama + ChromaDB semantic memory. MIT licensed.
Real-time URL threat intelligence Chrome extension with 12 client-side security checks.
XSS Injection Scanner is an automated security testing tool designed to detect Cross-Site Scripting (XSS) vulnerabilities in web applications
To associate your repository with the web-security-tool topic, visit your repo's landing page and select "manage topics."