03 Aug 2026
JavaScript
★ 16
Docker Registry UI provides a modern web interface for managing Docker registries with enhanced features such as vulnerability scanning through Trivy, bulk operations, and multi-registry support. It facilitates repository and tag management while offering storage analytics and a responsive design. The tool is designed for both local and production setups, allowing users to quickly deploy and manage registries efficiently.
03 Aug 2026
Python
★ 22
DiscourseMap is an advanced security scanner designed specifically for Discourse forum platforms, offering over 25 specialized security modules for comprehensive assessments. It features capabilities such as CVE detection, plugin analysis, and API testing, all optimized for quick performance and reliability, delivering detailed reports in multiple formats. The tool is well-suited for vulnerability detection and compliance verification, making it essential for securing Discourse environments.
03 Aug 2026
Python
★ 19
The Flowise Dual CVE PoC is a proof-of-concept tool for exploiting two critical vulnerabilities (CVE-2025-58434 and CVE-2025-59528) in the Flowise platform, enabling an attacker to achieve unauthenticated account takeover followed by remote code execution in an automated manner. It leverages a flawed password reset mechanism and unsanitized user input in JavaScript execution to facilitate these exploits, making it particularly dangerous for both cloud and self-hosted deployments. The tool includes modular functionality for conducting attacks and is intended solely for authorized security research purposes.
03 Aug 2026
Python
★ 14
Critikal is an autonomous security research agent specifically designed for smart contracts, capable of identifying exploitable vulnerabilities in blockchain protocols through a comprehensive analysis process. It ingests repository data, performs reconnaissance, maps the attack surface, and validates its findings, generating proof-of-concept tests using Foundry along with detailed audit reports in HTML and Markdown formats. Notable features include multi-model support for AI analysis, an integrated knowledge graph, and a user-friendly TUI demo for easy interaction.
03 Aug 2026
Python
★ 29
CorsOne is a specialized security testing tool for detecting Cross-Origin Resource Sharing (CORS) misconfigurations in web applications. It efficiently tests over 40 CORS bypass techniques, providing accurate results with low false positives and supporting advanced features such as customizable origin testing, proxy configurations, and multiple output formats for comprehensive reporting. The tool employs asynchronous operations for high performance and includes options for easy integration and flexible request handling.
03 Aug 2026
Python
★ 11
CloudVault is an enterprise-grade security scanner designed for multi-cloud storage environments, specifically targeting AWS S3, Google Cloud Storage, and Azure Blob. It offers advanced attack chain analysis, automated permission checking, and comprehensive risk scoring, facilitating real-time discovery of exposed cloud resources through certificate transparency monitoring. Notable features include interactive text user interface (TUI), alerts integration with communication platforms, compliance mapping, and various export formats for reporting and remediation.
03 Aug 2026
HTML
★ 38
ClawSecure is an independent security scanning and auditing platform designed for the OpenClaw ecosystem, which focuses on ensuring the integrity and safety of AI agent skills and workflows. It features a proprietary 3-Layer Audit Protocol that has examined over 3,000 skills against all OWASP ASI Top 10 security vulnerabilities, revealing that 41% of audited skills contain security flaws. It also offers free developer tools to enhance functionality and user experience within the OpenClaw framework.
03 Aug 2026
Python
★ 33
Claude Pentest Skills is a structured penetration testing skill pack designed for Claude Code that employs an OWASP-based methodology to streamline web application security assessments. It features a 6-gate validation process to filter out false positives, a series of interactive slash commands for efficient testing, and automated report generation in both markdown and PDF formats, ensuring compliance with verification and documentation standards. The tool improves the efficiency and reliability of pentesting workflows by maintaining consistent coverage tracking and enforcing scope before testing.
03 Aug 2026
Shell
★ 216
Claude Cybersecurity is an AI-powered code security audit tool designed to enhance vulnerability detection and compliance verification through the integration of 8 parallel specialist agents. It stands out by addressing issues often overlooked by static analysis tools, such as business logic flaws and contextual authorization checks, while supporting a broader range of programming languages and providing in-depth threat intelligence. Notable features include seamless integration with Claude Code, zero configuration requirements, and extensive coverage of vulnerabilities including IaC and container security.
03 Aug 2026
Rust
★ 41
Chaca is a native desktop web security scanner designed specifically for developers, providing fast and opinionated security audits of web applications through a user-friendly interface without requiring terminal use. It features both passive and active scanning capabilities, support for numerous content management systems and APIs, and generates detailed reports with filtering and export options. Additional highlights include a real-time progress dashboard, persistent scan history, and customizable scan presets, all built on a tech stack utilizing Rust, React, and Tauri.
03 Aug 2026
Python
★ 14
The cent-nuclei-templates repository provides a curated collection of 9,284 high-quality nuclei templates, generated and filtered through the cent tool for use with the Nuclei scanner. Its primary use case is to enhance vulnerability scanning by offering templates that are free from duplicates, noise, and outdated syntax, thereby improving accuracy and effectiveness in detecting vulnerabilities. Notable features include extensive deduplication processes, community-sourced additions, and ongoing maintenance scripts to ensure template quality and relevance.
03 Aug 2026
Shell
★ 50
CloudDefense.AI is an automated web application security testing tool designed to identify vulnerabilities such as SQL injection and cross-site scripting, enhancing overall application security. It supports various security assessments including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API scanning, facilitating a DevSecOps approach by integrating security assessments seamlessly into the development lifecycle. Notable features include its comprehensive application stack risk assessments and compatibility with multiple programming languages and integration points.
03 Aug 2026
Rust
★ 68
Cache Commander (ccmd) is a terminal UI tool designed for exploring, auditing, and managing developer cache directories on macOS and Linux. Its primary use case is to help developers identify and clean up accumulated cache data, scan for known CVEs, and manage outdated dependencies, all through an intuitive two-pane interface that supports multiple cache providers. Notable features include vulnerability scanning, reclaiming disk space from various cache types, and integration with AI for enhanced capabilities.
03 Aug 2026
Python
★ 335
BurpAPISecuritySuite is a professional-grade extension for Burp Suite that consolidates multiple functionalities for API reconnaissance, intelligent fuzzing, and AI-enhanced security testing into a single interface. It is designed to improve performance and usability by sharing resources across various tabs, thereby minimizing memory usage and CPU overhead while maintaining a stable and efficient testing environment. Notable features include support for REST, GraphQL, and SOAP APIs, as well as tools for passive discovery, fuzzing, and advanced security assessments based on the OWASP API Top 10 guidelines.
03 Aug 2026
Python
★ 34
BRS-XSS is an advanced XSS vulnerability scanner designed for modern web applications, providing deterministic and auditable detection capabilities. It features context-aware scanning, WAF evasion techniques, and a comprehensive knowledge base for payload management, along with a user-friendly web interface that supports real-time monitoring, detailed reporting, and customizable scanning options. Notably, it includes a Pentesting Task Tree strategy engine for adaptive testing, A/B testing for strategy comparison, and multiple report formats for enhanced analysis.
03 Aug 2026
Python
★ 11
aur_checker is a command-line security analysis tool designed for inspecting Arch Linux AUR PKGBUILD files to detect potential vulnerabilities. It employs a context-aware static analysis methodology, optionally enhanced with AI inspection, resulting in detailed risk assessments that include trust signals and explainable scoring. Key features include a user-friendly output format, JSON integration for CI purposes, and the ability to analyze multiple packages or files simultaneously.
03 Aug 2026
JavaScript
★ 190
OWASP ASST (Automated Software Security Toolkit) is an open-source, command-line web vulnerability scanner primarily focused on detecting security flaws in PHP and MySQL applications, while also capable of being extended to support additional programming languages. It provides detailed reports that not only identify vulnerabilities but also offer explanations and remediation strategies, thus educating developers on securing their code. ASST uniquely aligns its scanning approach with the OWASP Top 10 Web Application Security Risks, enhancing its effectiveness in comprehensive vulnerability assessment.
03 Aug 2026
Python
★ 12
ALNUR is an open-source end-to-end vulnerability scanner that evaluates application projects for security weaknesses, including CVEs in dependencies and potential risks in architecture, secret leaks, and agentic AI applications. Notable features include a comprehensive CVE scanner, in-depth architecture and standards compliance analysis, and support for various programming languages and frameworks, with customizable reporting options. The tool also offers optional LLM-enhanced analysis for generating executive summaries and remediation guidance.
03 Aug 2026
PHP
★ 15
A.S.E (Automated Security Evaluator) is a vulnerability management tool designed to automate the process of evaluating software security by integrating with OWASP Dependency-Track. Its primary use case is to assess vulnerabilities based on real-world exploitability and notify relevant teams via Slack, leveraging CVE scoring models such as CISA KEV and EPSS. Notable features include the automation of CycloneDX SBOM generation, tiered alerting for critical vulnerabilities, and configurable thresholds for alerts sent to teams.
03 Aug 2026
Go
★ 948
Xalgorix is an open-source AI-driven penetration testing platform that autonomously conducts comprehensive pentesting methodologies and verifies each finding through an independent verification process, ensuring the delivery of proven vulnerabilities rather than uncertain results. It is designed for self-hosting and supports a "bring-your-own-LLM" model, allowing integration with user-defined language models, while catering to both Linux environments and containerized implementations through Docker. Notable features include its autonomous execution, independent verification of findings, and the ability to run in a secured Docker container.
03 Aug 2026
Python
★ 13
WSHawk is an open-source toolkit designed for WebSocket security testing and web application penetration testing, integrating a CLI scanner, web dashboard, and desktop application. Notable features include stateful WebSocket testing, context-aware payload evolution, browser-assisted evidence collection using Playwright, and a comprehensive suite of web pentesting tools such as fuzzers and interceptors, all under the AGPL-3.0 license. The toolkit also supports project-backed workflows and offers various integrations and reporting formats for efficient security assessment.
03 Aug 2026
Go
★ 712
wscan is a comprehensive web security scanner designed for active, passive, and AI-driven penetration testing, addressing a wide range of vulnerabilities from the OWASP web vulnerability landscape. Key features include a browser-based WebUI for scan management, support for multiple scanning modes, an extensive library of built-in detection plugins, and integration with external POC engines like Nuclei, Xray, and Goby. Additionally, it offers an AI agent mode for automated testing and a reverse-connect platform for exploiting blind vulnerabilities.
03 Aug 2026
Python
★ 25
WebScan is an automated web security auditing tool designed to crawl, discover, and audit web applications. It features a robust plugin architecture with 41 plugins, offers multiple report formats, and is tailored for both site owners and bug hunters, providing user-friendly options like safe mode and detailed explanations of findings, as well as advanced stealth capabilities for more experienced users. Notable capabilities include request rate limiting, user-agent rotation, and proxy support to maintain the user's anonymity.
03 Aug 2026
Go
★ 12249
Vuls is an agent-less vulnerability scanner designed for Linux, FreeBSD, and macOS systems, written in Go, that automates the detection of vulnerabilities by continuously monitoring installed software against a variety of vulnerability databases. It generates regular reports that inform users about affected systems and related vulnerabilities, mitigating the risks of human oversight in the management of software updates. Notable features include high-quality scanning capabilities across major operating systems and integration with multiple security advisories and vulnerability databases.
03 Aug 2026
Go
★ 1057
Vigolium is a high-fidelity vulnerability scanner that offers two distinct scanning modes: Native Scan for fast and flexible multi-phase assessments, and Agentic Scan for autonomous, AI-driven code auditing. It features 317 scanner modules covering a wide array of vulnerabilities, including OWASP Top 10, and employs out-of-band testing to enhance accuracy. The tool is designed for both manual and automated security assessments, enabling comprehensive coverage of web applications and codebases.