InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
☆1,744Feb 16, 2026Updated last month
Alternatives and similar repositories for inql
Users that are interested in inql are comparing it to the libraries listed below
Sorting:
- GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)☆1,640Mar 11, 2024Updated 2 years ago
- Obtain GraphQL API schema even if the introspection is disabled☆1,407Dec 5, 2025Updated 3 months ago
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆818Jun 9, 2025Updated 9 months ago
- A toolkit for testing, tweaking and cracking JSON Web Tokens☆6,435May 1, 2025Updated 10 months ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,787Apr 26, 2024Updated last year
- GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations☆408Dec 24, 2022Updated 3 years ago
- A python script that finds endpoints in JavaScript files☆4,300Apr 13, 2024Updated last year
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,113Aug 14, 2024Updated last year
- HTTP parameter discovery suite.☆6,142Feb 20, 2025Updated last year
- SSRF (Server Side Request Forgery) testing resources☆2,483Oct 12, 2024Updated last year
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,063Jan 2, 2024Updated 2 years ago
- Automatic SSRF fuzzer and exploitation tool☆3,505Sep 4, 2025Updated 6 months ago
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆1,296Jan 26, 2024Updated 2 years ago
- Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practis…☆1,677May 24, 2025Updated 9 months ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,125Apr 21, 2024Updated last year
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.☆4,853Jan 1, 2025Updated last year
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability