OWASP Web Recon & Directory Discovery Platform
-
Updated
Oct 6, 2026 - Python
OWASP Web Recon & Directory Discovery Platform
🐛 Advanced web vulnerability scanner with 5-rule false-positive reduction, WAF evasion, and modern HTML reports
PERL-based website Admin Panel Finder - website security testing, and admin login path discovery.
A modern, console-based web penetration testing toolkit with a TUI. Features an HTTP/HTTPS proxy, active/passive vulnerability scanner, Repeater, Intruder, Spider, and more. Free & open-source.
Automated web-based vulnerability scanner designed to identify common security flaws such as SQL Injection and XSS. WAVSS crawls websites, performs comprehensive scans, and generates detailed PDF reports with remediation guidance.
🛡️ Burp Suite extension for automated access control bypass, path traversal & Web Cache Deception testing. Header spoofing, URL encoding, cache deception pipelines – all in one tool.
1 bilion % sure you web app has so much issue and i can find it easily ...
SubOracle is an advanced subdomain intelligence and attack surface reconnaissance framework designed for security researchers and penetration testers. It helps identify digital assets, discover subdomains, analyze external footprints, and improve visibility of an organization's online infrastructure through structured reconnaissance workflow.
🦄 All-in-one website intelligence tool. Replaces whois, whatmydns, wpscan & who.is in one free web app. Built for authorized security recon.
Try it Now... Recon, VA, & Business Logic Scan in one powerhouse tool. Expose hidden risks and logic flaws others miss. Zero noise, 360° visibility.
Stateless website privacy & security auditor. Scans for SSL/TLS encryption, cookies, trackers, and GDPR/ePrivacy compliance violations using Playwright.
Sentinel — Automated security assessment platform with local AI, CVE intelligence, and SOC monitoring. No API keys required.
Time-Based & Boolean Blind SQL Injection Testing Framework — v7.0.0
CYRASEC is a multi-engine web vulnerability scanner that combines tools like dirsearch and nuclei, using AI-assisted analysis to detect, prioritize, and report web security issues efficiently in one streamlined workflow.
Python-based web vulnerability scanner with ML severity classification and a live Streamlit dashboard. Detects XSS, SQLi, open redirects, missing headers, and exposed directories.
Herramienta premium y 100% estática para auditorías SEO, rendimiento Core Web Vitals y seguridad técnica en tiempo real desde el navegador.
XSS Injection Scanner is an automated security testing tool designed to detect Cross-Site Scripting (XSS) vulnerabilities in web applications
Google Cloud Security Command Center lab: detect, remediate, and re-scan an XSS vulnerability in a Flask application.
Small scale locally deployable python projects for offensive and defensive security.
aplikasi manajemen keamanan web berbasis PHP modular berkinerja tinggi yang dirancang untuk melindungi aplikasi web dari berbagai ancaman siber (seperti SQL Injection, XSS, RCE, LFI/RFI)
To associate your repository with the web-security-scanner topic, visit your repo's landing page and select "manage topics."