ππ¦ Dalfox is a powerful open-source XSS scanner and utility focused on automation.
β5,065Jun 15, 2026Updated this week
Alternatives and similar repositories for dalfox
Users that are interested in dalfox are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probingβ3,100Mar 7, 2026Updated 3 months ago
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.β4,981Mar 20, 2026Updated 2 months ago
- HTTP parameter discovery suite.β6,312Feb 20, 2025Updated last year
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grepβ1,438Sep 13, 2024Updated last year
- Fetch all the URLs that the Wayback Machine knows about for a domainβ4,474May 1, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- declutters url lists for crawling/pentestingβ1,560Feb 23, 2025Updated last year
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findinβ¦β7,713May 15, 2026Updated last month
- Gospider - Fast web spider written in Goβ2,966Apr 21, 2024Updated 2 years ago
- Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web applicationβ5,067Dec 21, 2024Updated last year
- Hidden parameters discovery suiteβ2,066Sep 8, 2024Updated last year
- A tool to check a bunch of URLs that contain reflecting params.β600Aug 4, 2024Updated last year
- httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.β10,053Updated this week
- A wrapper around grep, to help you grep for thingsβ2,116Jun 8, 2024Updated 2 years ago
- A python script that finds endpoints in JavaScript filesβ4,386Apr 13, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attβ¦β6,002Updated this week
- Accept URLs on stdin, replace all query string values with a user-supplied valueβ877Nov 23, 2022Updated 3 years ago
- An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flawsβ4,033Oct 4, 2025Updated 8 months ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.β6,257Aug 14, 2024Updated last year
- Fast passive subdomain enumeration tool.β13,846May 27, 2026Updated 3 weeks ago
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!β2,674Jun 11, 2026Updated last week
- Fast web fuzzer written in Goβ16,247Apr 26, 2026Updated last month
- Most advanced XSS scanner.β15,027Apr 26, 2025Updated last year
- The Swiss Army knife for automated Web Application Testingβ2,350May 8, 2024Updated 2 years ago
- Virtual machines for every use case on DigitalOcean β’ AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript filesβ2,466May 26, 2024Updated 2 years ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enablβ¦β29,204Updated this week
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Eβ¦β8,694Mar 21, 2026Updated 2 months ago
- Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokensβ¦β5,417Mar 13, 2026Updated 3 months ago
- Contextual Content Discovery Toolβ3,206Apr 29, 2024Updated 2 years ago
- Find domains and subdomains related to a given domainβ3,621Jun 7, 2024Updated 2 years ago
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,565Mar 8, 2026Updated 3 months ago
- Rockyou for web fuzzingβ3,166Mar 11, 2026Updated 3 months ago
- The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, fβ¦β4,393Sep 30, 2024Updated last year
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entβ¦β2,191Feb 23, 2026Updated 3 months ago
- Subdomain takeover vulnerability checkerβ1,565Sep 10, 2024Updated last year
- In-depth attack surface mapping and asset discoveryβ14,703Apr 17, 2026Updated 2 months ago
- A tool for adding new lines to files, skipping duplicatesβ1,641Jan 12, 2024Updated 2 years ago
- A collection of awesome one-liner scripts especially for bug bounty tips.β3,155Jul 29, 2024Updated last year
- Community curated list of templates for the nuclei engine to find security vulnerabilities.β12,520Updated this week
- Automatic SSRF fuzzer and exploitation toolβ3,569Sep 4, 2025Updated 9 months ago