An extension to find callback endpoints in the background while searching the Web
☆48Mar 26, 2026Updated 6 months ago
Alternatives and similar repositories for CallMe
Users that are interested in CallMe are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2…☆67Sep 18, 2026Updated 2 weeks ago
- ☆50Aug 2, 2025Updated last year
- A Caido plugin to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆51Apr 8, 2026Updated 5 months ago
- Android security tool that scans installed apps bytecode to discover content providers, file providers, and intent interfaces, then gener…☆20Mar 12, 2026Updated 6 months ago
- jxscout superpowers JavaScript analysis for security researchers☆468Apr 12, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- URLess is a simple but powerful tool that removes paths from URLs, generating multiple variations of the base domain. This is useful for …☆15Apr 1, 2025Updated last year
- MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.☆298Oct 5, 2024Updated 2 years ago
- Chrome extension for automating CSPT discovery☆164May 12, 2026Updated 4 months ago
- Repo containing walkthroughs to possibly pwn Admin Panels and Exposed Consoles☆17Sep 20, 2024Updated 2 years ago
- A modern postMessage tracker including additional features, inspired by Frans Rosens postmessage tracker. A port of chrome Manifest V3 "F…☆62Sep 12, 2025Updated last year
- HTTP testing platform for security researchers☆46Aug 21, 2026Updated last month
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆149Feb 4, 2026Updated 8 months ago
- MCP server that connects AI assistants to HackerOne for bug bounty hunting☆356Apr 7, 2026Updated 5 months ago
- A playground to practice SSRF Attacks against web apps☆17Oct 15, 2018Updated 7 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A Fuzzing skill based on purely what i know.☆43Jun 3, 2026Updated 4 months ago
- A fancier postMessage tracker with Chrome Manifest version V3 support and a few additional features, inspired by Frans Rosens postmessage…☆132Sep 12, 2025Updated last year
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆30May 23, 2026Updated 4 months ago
- Codex-style /goal command for Claude Code☆113May 8, 2026Updated 4 months ago
- A powerful Chrome extension for detecting and analyzing React Server Components (RSC) and Next.js App Router vulnerabilities☆16Updated this week
- web app monitoring automation☆15Jan 7, 2025Updated last year
- PP-finder Help you find gadget for prototype pollution exploitation☆208May 15, 2026Updated 4 months ago
- CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scr…☆716Updated this week
- 🤹 Caido AI Skills☆278Aug 13, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Stealth hybrid URL mapper☆38May 1, 2026Updated 5 months ago
- 0xJS is an AI-powered JavaScript Security Tool☆68Apr 16, 2026Updated 5 months ago
- a tool that compiles a csv of all h1 program stats☆50Jul 2, 2023Updated 3 years ago
- Search for secrets inside user data attached to EC2 instances on multiple AWS accounts☆16Jun 19, 2024Updated 2 years ago
- A tool for monitoring bug bounty programs across multiple platforms to track scope changes.☆35Sep 24, 2026Updated last week
- ☆10Nov 19, 2016Updated 9 years ago
- Burp plugin for jxscout☆25May 12, 2025Updated last year
- Burp Suite Extension with MCP Server to enhance manual application security testing☆55Jan 21, 2026Updated 8 months ago
- Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.☆22Apr 2, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- AWS S3 Bucket Finder.☆14Oct 28, 2025Updated 11 months ago
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆16Jul 17, 2024Updated 2 years ago
- 🔗 Source for the Caido plugin store☆22Updated this week
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications☆1,379Aug 7, 2025Updated last year
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Sep 28, 2026Updated last week
- Proof-of-concept CORS exploitation tool.☆35Sep 7, 2019Updated 7 years ago
- Easy discovery of assets☆13Jun 22, 2022Updated 4 years ago