Web Application Security
74 tools found
Request Map Generator
Generates a request map for a page to identify third parties, byte origin, and slowness.
WP Recon
Tool for vulnerability recognition and blackbox info gathering on WordPress sites.
ffuf
Fast web fuzzer for discovering hidden files and directories in web applications.
CAIDO
Modern, lightweight web security proxy with clean UI and modular design for web testing.
httpx
Fast HTTP toolkit for reliable probing using multi-threading and retryable HTTP requests.
GraphQL Security
Quickly assesses GraphQL app security for vulnerabilities and misconfigurations.
bwapp
Deliberately insecure web application with over 100 bugs for vulnerability learning.
Weevely
Web shell for post-exploitation with over 30 modules for admin tasks and access.
WPScan Online
Scanner tailored to detect and assess vulnerabilities in WordPress websites with precision.
Nikto
Web server scanner detecting dangerous files, outdated versions, and config vulnerabilities.
LazyXSS
Automates reflected XSS detection in URLs, generating clean, multi-page HTML reports.
XSStrike
XSS detection suite with parsers, intelligent payload generator, and fast crawler.
DVWA
Intentionally vulnerable PHP/MariaDB web application for security testing and learning.
HTTP Toolkit
Open-source tool to intercept, inspect, and modify HTTP(S) traffic for testing and debugging.
aikido
DAST tool for monitoring apps/APIs to detect OWASP risks like XSS, SQLi, and CSRF.
Arjun
Tool to find valid HTTP query parameters in URLs, with an extensive dictionary.
proxify
Multifunction proxy with filtering, traffic replay and upstream support for Burp integration.
WAF Bypass Tool
WAF Bypass Tool is an open source tool to analyze the security of any WAF for False Positives and False Negatives using predefined and customizable payloads. Check your WAF before an attacker does. WAF Bypass Tool is developed by Nemesida WAF team with the participation of community.
Pentest Mapper
Burp extension to map API flows and link them to custom security test checklists.
SafeLine
SafeLine is a self-hosted WAF(Web Application Firewall) to protect your web apps from attacks and exploits.
Indusface
PTaaS platform for testing apps/APIs, logic flaws, and continuous malware monitoring.
backslash
Burp extension for detecting server-side injections with evasive, precise techniques.