A modern, console-based web penetration testing toolkit with a TUI. Features an HTTP/HTTPS proxy, active/passive vulnerability scanner, Repeater, Intruder, Spider, and more. Free & open-source.
-
Updated
Oct 5, 2026 - Python
A modern, console-based web penetration testing toolkit with a TUI. Features an HTTP/HTTPS proxy, active/passive vulnerability scanner, Repeater, Intruder, Spider, and more. Free & open-source.
A Flask-based phishing detection platform for analyzing URLs, emails, and SMS messages using a rule-based risk assessment engine.
URLUNIQ 2.0 is an advanced offline URL normalization, canonicalization, deduplication, classification, filtering, analysis, and reporting toolkit built for security researchers, bug bounty hunters, and large URL datasets.
Write-ups from PortSwigger Web Security Academy labs: SQL Injection, XSS, and more as I progress
Burp Suite extension for HTTP verb tampering testing using Montoya API.
aplikasi manajemen keamanan web berbasis PHP modular berkinerja tinggi yang dirancang untuk melindungi aplikasi web dari berbagai ancaman siber (seperti SQL Injection, XSS, RCE, LFI/RFI)
Turn Burp Suite XML dumps into compact, LLM-ready Markdown reports.
Amba2Pen is a Python-based tool designed to streamline the penetration testing process by automating various pentest tasks.
Air-gapped LLM-assisted web application pentest triage — Burp Suite extension + local Ollama + ChromaDB semantic memory. MIT licensed.
An automated SQL injection testing to uncover backend database vulnerabilities
Real-time URL threat intelligence Chrome extension with 12 client-side security checks.
XSS Injection Scanner is an automated security testing tool designed to detect Cross-Site Scripting (XSS) vulnerabilities in web applications
S.H.O.A.V. : a deterministic-core AI bodyguard that shields autonomous web agents from clickjacking, dark patterns and hidden prompt injection. Built on Auto Browser for any CLI-capable agent. Genesis Hackathon 2026, Track 03.
Didaktisches Web-Security & HTTP-Header Audit-Framework (227 Punkte) mit nativer Zero-Regex-Engine für maximale Performance & ReDoS-Schutz. Bietet tiefe Kontext-Risikomatrix (diverse Seitentypen), Soft-404-Entrapment, WAF/CDN-Fingerprinting, automatische .htaccess-Direktiven und vollständige DSGVO-Konformität (In-Memory/No-DB).
To associate your repository with the web-security-tool topic, visit your repo's landing page and select "manage topics."