Web Application Tools

462 tools
PHP-Antimalware-Scanner
PHP-Antimalware-Scanner
Open Source Exploitation Scanning & Enumeration

AMWScan (PHP Antimalware Scanner) is a free tool to scan php files and analyze your project to find any malicious code inside it.

phpsploit
phpsploit
Open Source Exploitation Post-Exploitation

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Pinakastra
Pinakastra
Free Reconnaissance Web Application

AI-powered pentesting framework with automated recon and exploitation. Multi-source subdomain discovery, active vuln testing (XSS/SQLi/SSRF/…

pipelock
pipelock
Open Source Web Application

Open-source AI agent firewall for MCP security: agent egress control, DLP, SSRF, and prompt injection defense.

plecost
plecost
Free Exploitation Web Application

Plecost - Professional WordPress Security Scanner

pphack
pphack
Open Source Exploitation Web Application

The Most Advanced Client-Side Prototype Pollution Scanner

privatecollaborator
privatecollaborator
Open Source Web Application

A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate

project-foxhound
project-foxhound
Open Source Web Application

A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozilla…

prokzee
prokzee
Free Web Application

A cross-platform desktop application for HTTP/HTTPS traffic interception and analysis, built with Go. Features modern UI, traffic manipulati…

public-skills-builder
public-skills-builder
Free Scanning & Enumeration Web Application

Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed

pwn
pwn
Open Source Reconnaissance Reverse Engineering

PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.

PyCript
PyCript
Open Source Web Application

Burp Suite extension to decrypt/encrypt any encrypted traffic (AES/RSA/Encodings and more) with custom code in any language

pyhtools
pyhtools
Open Source Web Application

A Python Hacking Library consisting of network scanner, arp spoofer and detector, dns spoofer, code injector, packet sniffer, network jammer…

QuickXSS
QuickXSS
Open Source Web Application

Automating XSS using Bash

rag-security-scanner
rag-security-scanner
Open Source Exploitation Scanning & Enumeration

RAG/LLM Security Scanner identifies critical vulnerabilities in AI-powered applications, including chatbots, virtual assistants, and knowled…

react2shell-ultimate
react2shell-ultimate
Open Source Scanning & Enumeration Web Application

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, lo…

realm
realm
Open Source Exploitation Post-Exploitation

Realm is a cross platform Red Team engagement platform with a focus on automation and reliability.

reconftw
reconftw
Open Source Reconnaissance Web Application

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding o…

reconic
reconic
Open Source Reconnaissance Web Application

A Powerful Network Reconnaissance Tool for Security Professionals

reconmap
reconmap
Open Source Exploitation Web Application

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from …

RED_HAWK
RED_HAWK
Open Source Reconnaissance Web Application

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

rekono
rekono
Open Source Reconnaissance Web Application

Pentesting automation platform that combines hacking tools to complete assessments

rengine
rengine
Open Source Reconnaissance Scanning & Enumeration

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engi…

requests-ip-rotator
requests-ip-rotator
Open Source Web Application

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.