> cat /dev/github | grep security-tools

Php

prestascansecurity

2026-08-25 PHP ★ 61
PrestaScan Security is a PrestaShop module designed to scan PrestaShop websites for malware and known vulnerabilities in both the core and its modules. It features an intuitive installation process, regular vulnerability alerts, and is compatible with multiple PrestaShop versions, ensuring comprehensive security for e-commerce sites. This free and open-source tool is supported by a dedicated team of security experts who continually monitor and audit for potential threats.

KrazePlanetCTF

2026-08-22 PHP ★ 12
KrazePlanetCTF is an open-source web security training platform that features over 260 interactive challenges within isolated per-user sandboxes, enabling hands-on learning for cybersecurity professionals. Its primary use case is to facilitate practical training in web security through real-world scenarios, while notable features include Docker-based deployment and easy management via command-line tools for viewing logs and controlling the platform's state.

Ethical-Hacking

2026-08-21 PHP ★ 49
The Ethical-Hacking repository provides a comprehensive step-by-step guide for learning cybersecurity and ethical hacking using Kali Linux. It covers foundational knowledge in networking and Linux commands, introduces tools like Nmap and Metasploit, and offers practice platforms for hands-on experience. Notable features include recommended resources, structured learning paths, and additional guidance on specialized areas like web application security and certifications.

cybersecurity-pam

2026-08-03 PHP ★ 28
The Privileged Access Management (PAM) repository is a curated collection of resources that encompasses software best practices, techniques, libraries, frameworks, and educational materials related to securing and managing privileged access to critical assets in cybersecurity. Notable features include categorized content for various platforms such as Linux and Windows, as well as practical guides on privilege escalation methods and access control strategies. This community-driven initiative aims to facilitate knowledge sharing and enhance best practices in the field of PAM.

AIO-Pentesting

2026-08-03 PHP ★ 49
AIO-Pentesting is a comprehensive resource for penetration testers, encapsulating various methodologies, tools, and commands necessary for conducting thorough security assessments. It categorizes content into phases, covering pre-intrusion and intrusion techniques for both Linux and Windows environments, along with additional materials such as notes for certifications like OSCP and OSWE. Notable features include organized documentation on common pentesting stages, forensics, and various exploitation techniques, as well as links to essential vulnerability databases and binary libraries.

LDAP-credentials-collector-backdoor-generator

2026-08-03 PHP ★ 58
The LDAP-credentials-collector-backdoor-generator is a malicious tool designed to create backdoor scripts that log LDAP user credentials during HTTP basic authentication. Its primary use case involves injecting the generated backdoor into a target web application to capture sensitive username and password information from users who access the site. Notable features include customizable backdoor filename generation and the ability to store captured credentials in a file for easy retrieval by the attacker.

ReHTTP

2026-08-03 PHP ★ 78
ReHTTP is a PowerShell-based HTTP shell that features a web user interface, designed primarily for remote management and control of clients on a Windows platform. Key functionalities include executing PowerShell commands, managing client connections, and creating custom modules and variables, along with sophisticated event handling capabilities for connection management. This tool also supports scheduled tasks and offers a history feature for command execution, enhancing its usability in system administration and penetration testing contexts.

checkpoint

2026-08-03 PHP ★ 114
Checkpoint is a Laravel security scanner designed to audit applications for common vulnerabilities, encompassing checks for known CVEs, hardcoded secrets, and potential misconfigurations through a single Artisan command (`php artisan checkpoint:scan`). It performs a comprehensive analysis, including Composer and NPM CVE audits, environment configuration validation, file permissions checks, and scans for risks like SQL injection and XSS vulnerabilities. Notable features include the ability to detect sensitive data exposure and misconfigured security settings, making it an essential tool for securing Laravel applications.

intercept

2026-08-03 PHP ★ 60
Intercept is a modular middleware framework designed for the Laravel AI SDK, providing essential guardrails across security, observability, performance, and guidance for AI agents. By acting as an intermediary, it enhances prompt management before sending requests to AI providers, ensuring improved oversight and control. Key features include a suite of reusable middleware components, comprehensive documentation, and ongoing roadmap updates for future enhancements.

mercator

2026-08-03 PHP ★ 548
Mercator is an open source web application designed for dynamic mapping of information systems, providing IT professionals with a comprehensive overview of their digital environments. It enables users to visualize dependencies, track compliance, generate architectural reports, and facilitate risk management through features like graphical representations, compliance monitoring, and integration with security tools. Notably, Mercator supports multi-user collaboration and offers a REST API for seamless system integration, making it a valuable asset for organizations aiming to enhance information system governance.

PermCheck

2026-08-03 PHP ★ 11
PermCheck is a lightweight tool designed for verifying proper executable permissions on files within a PHP project. By utilizing a customizable XML configuration file, it allows users to specify which directories and files should be executable, thus enhancing project consistency and security. Notable features include support for various PHP versions, minimal dependencies, and integration with the Symfony Console Component for ease of use.

sussyfinder

2026-08-03 PHP ★ 79
SussyFinder is a PHP web application designed to scan directories for files with specific extensions, particularly PHP scripts, and identify potential malicious content through token and pattern analysis. It features a token-based comparison method that accounts for obfuscation techniques, allows for MD5 hash-based whitelisting and blacklisting, and presents results with color highlights for easy identification. The tool is particularly useful for web server environments but requires cautious use due to the potential for false positives and file deletion capabilities.

YAPS

2026-08-03 PHP ★ 84
YAPS is a lightweight PHP reverse shell that operates as a single file, allowing users to execute commands on remote systems through a TCP listener. It features customizable password protection, enumeration capabilities for gathering system information, and the ability to manage concurrent connections and execute PHP code remotely. Notably, it can auto-download enumeration tools, exploit known vulnerabilities like CVE-2021-4034, and send shellcode to the target host while supporting operations on both Linux and Windows in future updates.

non-alphanumeric-webshell

2026-08-03 PHP ★ 21
The Non-Alphanumeric WebShell in PHP is a tool designed to execute code on a server by exploiting certain user input vulnerabilities, particularly targeting web application firewalls (WAFs) that filter common characters. Its notable feature is the ability to construct a functioning shell without relying on blocked alphanumeric characters, using techniques such as XOR operations and leveraging PHP's handling of arrays and string conversions. This tool serves as a proof of concept for code execution bypass methods in security testing scenarios.

CTF-Game

2026-08-03 PHP ★ 18
The Pixels Camp Security CTF Dashboard is a web-based tool designed to manage Capture The Flag (CTF) security competitions, facilitating both participant engagement and organizer oversight. Key features include a public dashboard to display real-time CTF progress, a private area for teams to submit answers and track their performance, as well as a backoffice for administrative tasks, including logging submissions and issuing announcements. The tool allows for seamless competition management through start/stop controls, pause functionality, and team token authentication.

Karkinos

2026-08-03 PHP ★ 418
Karkinos is a lightweight penetration testing tool designed for ethical hacking and CTF competitions, offering functionalities such as encoding/decoding, encryption/decryption, and hash cracking/generating. It features three distinct modules and includes a new port scanning demo, allowing users to test applications and networks they have authorization to assess. Built primarily using PHP and Python, Karkinos is compatible with any server capable of hosting PHP and is designed to be Raspberry Pi Zero friendly.

0-click-RCE-Exploit-for-CVE-2024-10924

2026-08-03 PHP ★ 14
This repository provides a proof-of-concept exploit for CVE-2024-10924, allowing an attacker to bypass authentication and two-factor authentication in the Really Simple Security WordPress plugin to achieve remote command execution (RCE). The script automates the process of impersonating an administrator, uploading a malicious plugin, verifying interaction with the payload, and establishing an interactive remote shell. Notably, it operates pre-authentication, requiring only the target URL and a malicious plugin as input.

bug-bounty

2026-08-03 PHP ★ 132
Bug Bounty is a comprehensive knowledge base designed for security researchers, penetration testers, and bug bounty hunters, featuring methodologies, cheatsheets, automation tools, wordlists, and real-world write-ups. Its primary use case involves equipping users with the necessary resources for web penetration testing, API security, cloud exploitation, and modern vulnerability assessment techniques. Notable features include battle-tested methodologies and a focus on ethical hacking practices, underscoring the importance of authorized testing only.

laravel-security-checker

2026-08-03 PHP ★ 51
The Enlightn Security Checker for Laravel is a tool designed to identify dependencies with known security vulnerabilities within Laravel applications. Utilizing an Artisan command, it allows developers to scan their composer.lock file for issues, with options to customize output format, exclude development dependencies, and manage caching directories for advisory databases. Notable features include flexibility in command parameters and integration with Composer for effective vulnerability management.

security-checker

2026-08-03 PHP ★ 339
Enlightn Security Checker is a command-line tool designed to identify dependencies in your application with known security vulnerabilities by leveraging the Security Advisories Database. Its primary use case is to enhance application security during development, allowing for checks against defined vulnerabilities through commands that can display results in various formats and exclude development dependencies. Key features include customizable output formats, the ability to exclude certain vulnerabilities, and an API for integration into other codebases.

A.S.E

2026-08-03 PHP ★ 15
A.S.E (Automated Security Evaluator) is a vulnerability management tool designed to automate the process of evaluating software security by integrating with OWASP Dependency-Track. Its primary use case is to assess vulnerabilities based on real-world exploitability and notify relevant teams via Slack, leveraging CVE scoring models such as CISA KEV and EPSS. Notable features include the automation of CycloneDX SBOM generation, tiered alerting for critical vulnerabilities, and configurable thresholds for alerts sent to teams.

symfony-security-auditor

2026-08-03 PHP ★ 87
Symfony Security Auditor is an AI-driven security auditing tool designed for Symfony applications, focusing on identifying application-level flaws that traditional static analysis tools may overlook. It features an adversarial Attacker and Reviewer loop to validate vulnerabilities and produces reports in multiple formats, including JSON and HTML. The auditor can operate in two modes: as a standalone CLI tool or integrated into Symfony applications, providing flexibility for different auditing needs.

slopShell

2026-08-03 PHP ★ 230
slopShell is a PHP webshell designed for educational exploitation purposes, primarily allowing unauthorized file uploads to potentially compromised servers. Notable features include mutual TLS support in future iterations, a more refined dropper to evade detection, and the ability to interface with a personal database of cloud entities. This tool is intended for use in controlled environments and is equipped with capabilities for randomized user agents to minimize detection risks.

Gecko

2026-08-03 PHP ★ 153
Gecko is a web backdoor tool designed to facilitate exploitation and control of compromised systems, primarily targeting web applications. It features functionality for bypassing various HTTP error responses, auto-rooting capabilities, and the ability to manage backdoors, admin accounts, and file handling operations. Notably, it includes a Backdoor Destroyer and supports both Linux Exploit Suggester functionality and user account modifications, making it a versatile tool for penetration testing and system administration.

Xviews

2026-08-03 PHP ★ 12
Xviews is a traffic generation tool designed to increase the number of views on specified websites, particularly effective with Blogspot. It features a proxy support mechanism, allows simultaneous requests, and provides real-time monitoring through terminal color displays, enhancing user control over traffic parameters. The tool is intended strictly for educational purposes, with a clear warning against potential misuse.

php-reverse-shell

2026-08-03 PHP ★ 574
The PHP Reverse Shell is a versatile tool designed to create reverse shells using PHP scripts across different operating systems, including Linux, macOS, and Windows. It automatically detects the OS and works with both `ncat` and `multi/handler`, offering educational utilities for establishing reverse shells and executing file upload/download functionalities. Notably, it supports multiple PHP versions and includes specific scripts for different environments, enhancing its adaptability for penetration testing scenarios.

i-Detector

2026-08-03 PHP ★ 21
i-Detector is an educational tool designed for simulating Instagram login and two-factor authentication (2FA) mechanisms, aimed at ethical hacking and cybersecurity training. It includes a simple fake login page that collects user credentials via a data management script, which runs on various platforms including Windows, Linux, and Android. The tool is intended for practical learning experiences in social engineering techniques and is continuously updated with features in its main project repository.

TeleStrike

2026-08-03 PHP ★ 44
TeleStrike is a red team utility for simulating penetration tests and conducting security audits on Telegram accounts, designed solely for authorized assessments and educational purposes. Its notable features include two-factor authentication enumeration, session hijacking simulations, automated social engineering flows, and customizable modules for various attack vectors. The toolkit serves to evaluate the resilience of Telegram's authentication mechanisms against real-world attack scenarios.

zerdecalistops

2026-08-03 PHP ★ 32
Zerdecalistops is an optimized wordlist collection designed for cybersecurity researchers and penetration testers, tailored by Zencefil Efendi and enhanced with a dashboard interface. Its primary use case is to provide comprehensive and up-to-date datasets—including usernames, passwords, and fuzzing payloads—essential for cybersecurity operations. Notable features include its extensive compilation of resources and user-friendly dashboard for easy access.

Magento-Polyshell-RCE

2026-08-03 PHP ★ 29
Magento PolyShell is an advanced exploitation toolkit designed for unauthenticated remote code execution (RCE) on Magento 2.x through polyglot file uploads via the REST API. It tests over 45 PHP extension variants while utilizing multi-header support, server fingerprinting, and advanced WAF bypass techniques to maximize exploitation success across a wide range of environments. Key features include interactive and CLI modes, categorization of results by target, and extensive post-exploitation capabilities for system information retrieval.

wordpress-malware

2026-08-03 PHP ★ 71
WordPress Malware is a collection of malware samples sourced from compromised WordPress websites, organized by the date they were discovered. The repository includes custom PHP functions commonly used for malicious actions, such as file modification and execution of PHP code. This tool serves as a resource for developing malware detection solutions and is utilized by associated cPanel plugins for scanning and mitigating malware threats.

dj-camphish

2026-08-03 PHP ★ 11
dj-camphish is a browser-based toolkit designed for ethical hacking, OSINT training, and privacy awareness demonstrations, allowing users to capture webcam snapshots with permission and redirect them to a custom URL. Key features include an intuitive admin panel for managing captures, secure CSRF protection, responsive design for mobile and desktop, and a straightforward setup process without the need for port forwarding.

rome-webshell

2026-08-03 PHP ★ 70
Rome WebShell is a lightweight PHP webshell designed for educational use, featuring a fully interactive file explorer that allows users to browse directories and upload files directly from their browser. It enables command execution without URL encoding while offering MD5 password protection for access control, alongside a customizable and responsive FlatUI interface. Additionally, the tool includes an obfuscated version to enhance security against detection.

sqlscan

2026-08-03 PHP ★ 262
sqlscan is a web scanning tool designed to detect SQL injection vulnerabilities in websites quickly. Its primary use case is for security testing and penetration testing, enabling users to scan individual URLs or lists of URLs for potential security flaws. Notable features include multi-platform support, speed, and the ability to utilize sitemaps for enhanced scanning results.

awesome-skills-security

2026-08-03 PHP ★ 372
The "Awesome Security Skills" repository offers a curated collection of security testing resources in the form of agent skills for use with various AI agents. Its primary use case is to provide security professionals with immediate access to essential tools such as wordlists, payloads, and patterns for tasks like penetration testing, bug bounty research, and educational demonstrations. Notable features include integration with over 60 supported agents, organized categories for diverse security tasks, and comprehensive LLM security testing methodologies.

pentest

2026-08-03 PHP ★ 740
The Pentester Guide is a comprehensive resource aimed at penetration testers, providing a curated collection of tools, methodologies, educational materials, and practical labs. It includes sections on certifications, bug bounty platforms, and independent pentesting resources, making it an essential tool for both novice and experienced cybersecurity professionals. Notable features include a detailed roadmap for cybersecurity learning and multiple links to pentesting practice environments.

VexiumCTF

2026-08-03 PHP ★ 12
VexiumCTF is an intentionally vulnerable web application framework designed for security training and education. It facilitates hands-on practice with security vulnerabilities through Docker or XAMPP setups, featuring a web interface and a database management system via phpMyAdmin for effective experimentation. Key functionalities include easy configuration for SQL initialization and comprehensive logs to aid analysis during testing sessions.

WebVulnLab

2026-08-03 PHP ★ 60
WebVulnLab is a comprehensive learning platform designed for identifying and exploiting web vulnerabilities within a controlled and secure environment. It features more than 30 types of vulnerabilities for practical training, an enhanced user-friendly interface for easier management of Docker containers, and a control panel for overseeing active containers, ensuring an effective ethical hacking practice.

cywise

2026-08-03 PHP ★ 20
Cywise is a cybersecurity solution designed for both on-premises and SaaS environments, enabling users to scan and secure their web-facing and internal infrastructures. It features a robust vulnerability scanner that monitors for over 50,000 vulnerabilities with automated remediation, alongside active data leak monitoring and intelligent honeypots to detect and analyze potential threats. This tool is particularly suitable for small to medium-sized enterprises looking to enforce comprehensive security measures while maintaining control over their data and infrastructure.

PHP-Antimalware-Scanner

2026-03-30 PHP ★ 780
PHP Antimalware Scanner is a PHP-based tool designed to scan projects for malicious code embedded within PHP files. Its primary use case is to detect potential malware through an interactive console interface or in a reporting mode that generates results in HTML or text. Notable features include customizable scanning options for file paths, action prompts upon detection of malware, and compatibility with various PHP configurations.

IP-Tracer

2026-03-22 PHP ★ 2819
Track any ip address with IP-Tracer. IP-Tracer is developed for Linux and Termux. you can retrieve any ip address information using IP-Tracer.

MISP

2026-03-22 PHP ★ 6494
MISP (core software) - Open Source Threat Intelligence and Sharing Platform

p0wny-shell

2026-03-22 PHP ★ 2742
Single-file PHP shell

penetration-testing-cheat-sheet

2026-03-22 PHP ★ 842
Work in progress...

phishing-frenzy

2026-03-22 PHP ★ 885
Ruby on Rails Phishing Framework

server

2026-03-22 PHP ★ 1802
Hashtopolis - distributed password cracking with Hashcat

wwwolf-php-webshell

2026-03-22 PHP ★ 764
WhiteWinterWolf's PHP web shell