Burp Suite extension that offers a toolkit for testing GraphQL endpoints.
☆203Aug 5, 2024Updated last year
Alternatives and similar repositories for graphquail
Users that are interested in graphquail are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Obtain GraphQL API schema even if the introspection is disabled☆1,474Dec 5, 2025Updated 6 months ago
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆472Oct 3, 2023Updated 2 years ago
- A browser bookmark to show hidden fields and enable disabled fields on a web page☆20Oct 29, 2023Updated 2 years ago
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆104Mar 6, 2025Updated last year
- Mine URLs from Browser's Heap Snapshot for fun and profit☆65Aug 9, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- 🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️☆228May 22, 2023Updated 3 years ago
- MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.☆300Oct 5, 2024Updated last year
- Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist☆1,519Jan 8, 2026Updated 5 months ago
- An IIS short filename enumeration tool☆1,174Nov 25, 2024Updated last year
- Unofficial documentation for the great tool Param Miner☆186Aug 21, 2022Updated 3 years ago
- GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations☆411Dec 24, 2022Updated 3 years ago
- Quick tool to create custom wordlists like how fuzzers work☆10Sep 29, 2023Updated 2 years ago
- ☆149Dec 23, 2022Updated 3 years ago
- Extract URLs, paths, secrets, and other interesting bits from JavaScript☆1,839May 22, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Saves pages to Wayback machine☆12Dec 2, 2024Updated last year
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆853May 16, 2026Updated 3 weeks ago
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications☆1,354Aug 7, 2025Updated 10 months ago
- CrackQL is a GraphQL password brute-force and fuzzing utility.☆349Aug 3, 2024Updated last year
- ☆438Jun 1, 2021Updated 5 years ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆754Dec 19, 2023Updated 2 years ago
- A tool to inspect and attack version 1 GUIDs☆239Oct 13, 2022Updated 3 years ago
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆1,044Jun 6, 2026Updated last week
- De-clutter a list of URLs☆390Mar 8, 2026Updated 3 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- A Firefox Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆28Dec 9, 2024Updated last year
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆81Oct 20, 2023Updated 2 years ago
- Security Auditor Utility for GraphQL APIs☆652Nov 20, 2025Updated 6 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆38Mar 4, 2025Updated last year
- Identify virtual hosts by similarity comparison☆141Mar 18, 2026Updated 2 months ago
- Jeeves SQLI Finder☆215May 13, 2022Updated 4 years ago
- ☆183Aug 23, 2025Updated 9 months ago
- GraphQL automated security testing toolkit☆335Feb 20, 2024Updated 2 years ago
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzer☆385May 19, 2023Updated 3 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- ☆105Jan 3, 2023Updated 3 years ago
- Generate tens of thousands of subdomain combinations in a matter of seconds☆276Sep 25, 2023Updated 2 years ago
- 🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.☆976Jan 10, 2025Updated last year
- Find subdomains on GitLab.☆106Apr 28, 2024Updated 2 years ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆850May 13, 2026Updated last month
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆334Jul 11, 2025Updated 11 months ago
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆141Sep 16, 2024Updated last year