If you found this, you are among the truly lucky, to be given providence to my curated and often custom wordlists. Enjoy, buddy, you've ear…
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
Common Web Managers Fuzz Wordlists
Mike North's Web Security Course
18 Claude Code skill files for smart contract security — built from 2,749 Immunefi reports, 681 DeFiHack reproductions, and real hunt experi…
This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains …
An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vul…
A Python tool to automate some dorking stuff to find information disclosures.
Scripts for solving WebSecurity Academy labs of PortSwigger using Python
A collection of advanced PHP and ASPX web shells designed to bypass security measures.
Web application fuzzer that replaces any reference to the FUZZ keyword with a payload value. Supports multiple encoders, filters, iterators,…
Web scanner that identifies web technologies including CMS, blogging platforms, analytics packages, JavaScript libraries, server frameworks,…
Developed by Andrew Horton urbanadventurer and Brendan Coles bcoles
This is a simple python tool to automatically deface webdav vulnerable websites.
This is more of a checklist for myself. May contain useful tips and tricks.
Custom wordlist, updated regularly
[Custom || Automated] Curation & Collection of BugBounty Wordlists
WordPress Auto Admin Account Creation and Reverse Shell cve-2024-27956 automates the process of creating a new administrator account in a Wo…
Collection of malware files found on hacked WordPress sites
Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield
You can Support me by register or use digitalocean
A proof-of-concept WordPress plugin fuzzer
A fast WordPress plugin enumeration tool
WordPress security scanner. Enumerates WordPress installations for vulnerable plugins, themes, and configurations. Checks usernames, timthum…