A comprehensive WordPress vulnerability scanner and exploitation framework for authorized penetration testing. This tool automatically detects and exploits multiple WordPress security vulnerabilities (CVEs) to help security professionals identify and patch weaknesses.
☆72May 21, 2026Updated 2 months ago
Alternatives and similar repositories for Mephisto
Users that are interested in Mephisto are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Full and complete RCE exploit for Magento Polyshell☆28Apr 9, 2026Updated 3 months ago
- WordPress XML-RPC & WP-Login Bruteforce + Auto Uploader Powerful asynchronous bruteforce tool for WordPress sites via wp-login.php and …☆25Apr 22, 2025Updated last year
- SSRFHunter☆18Jan 17, 2026Updated 6 months ago
- Beelzebub all in one Hacking Tools, Shell finder, Zone-H Grabber, ReverseIP, SMTP Finder, XMLRPC BF and more☆56May 27, 2025Updated last year
- PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0☆20Jul 20, 2026Updated 2 weeks ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Tool to bypass 40X response codes.☆46Sep 18, 2022Updated 3 years ago
- My Main App Hacking CheckList☆33Jun 20, 2026Updated last month
- Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, …☆180May 12, 2026Updated 2 months ago
- Kali Linux Polyglot Harness for Autonomous Pentesting/Cyber Security☆125Updated this week
- CVE-2025-55182-bypass-waf☆31Jan 8, 2026Updated 6 months ago
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆21Jul 24, 2026Updated last week
- FortiSandbox RCE Scanner — CVE-2026-39808☆26Apr 21, 2026Updated 3 months ago
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆28May 23, 2026Updated 2 months ago
- Apkx-Hunter is an Android Static Analysis Framework in Debian Package written entirely in C with OWASP MASVS scanning with 15 categories …☆84Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier☆241Jul 7, 2026Updated 3 weeks ago
- ☆36May 5, 2026Updated 2 months ago
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆16Jul 2, 2026Updated last month
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆34May 15, 2026Updated 2 months ago
- NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF☆75May 15, 2026Updated 2 months ago
- A shellcode loader generator with support for multiple injection techniques, built for red team engagements.☆99Jul 1, 2026Updated last month
- It serves as a practical guide for security researchers to identify and test WordPress targets effectively during bug bounty hunting.☆27Jul 19, 2026Updated 2 weeks ago
- Three LLMs review your design plan in parallel — paste 30 lines into your CLAUDE.md, no install needed.☆15May 2, 2026Updated 3 months ago
- A collection of awesome one-liners for bug bounty hunting.☆60Apr 12, 2026Updated 3 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Passive leak enumeration tool.☆565Updated this week
- Nuclei templates which I wrote myself☆10Jan 8, 2022Updated 4 years ago
- Stealth Windows keylogger.☆54Jan 11, 2026Updated 6 months ago
- Burp_Suite-Antigravity_AI-Bug_Bounty_Hunter☆64Feb 9, 2026Updated 5 months ago
- A comprehensive Python-based OSINT (Open Source Intelligence) tool for email and phone number verification with breach detection, social …☆72Sep 9, 2025Updated 10 months ago
- Stealth hybrid URL mapper☆26May 1, 2026Updated 3 months ago
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆18May 20, 2026Updated 2 months ago
- The ultimate pentesting companion. Keep all your pentesting artifacts in one place.☆68Jul 27, 2026Updated last week
- GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & m…☆264Mar 28, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Chrome DevTools HTTP workbench with built-in AI.☆19Dec 9, 2025Updated 7 months ago
- Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest☆333Jul 3, 2026Updated last month
- A tool that helps you find the real IP addresses hiding behind Cloudflare.☆636Jul 6, 2026Updated 3 weeks ago
- CVE-2026-21643☆18Mar 28, 2026Updated 4 months ago
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 5 months ago
- API URL fuzzer that cross-joins hosts and paths into normalized URLs, probes them over HTTP, and reports responding endpoints.☆30Jun 11, 2026Updated last month
- Fortinet FortiClientEMS improper access control☆37Apr 20, 2026Updated 3 months ago