⚔️ Community maintained directory, MCP and API of 3,000+ active bug bounty programs and VDPs
☆429Sep 19, 2026Updated this week
Alternatives and similar repositories for bug-bounties
Users that are interested in bug-bounties are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An automated GitHub Actions-based crawler that fetches and updates public scopes from popular bug bounty platforms (like Hackerone/Bugcro…☆99Updated this week
- A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms…☆1,115Updated this week
- Community curated list of templates for the nuclei engine to find security vulnerabilities.☆111Nov 24, 2025Updated 9 months ago
- Community curated list of public bug bounty and responsible disclosure programs.☆1,352Updated this week
- Asset inventory of over 800 public bug bounty programs.☆1,610Feb 14, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Automate Recon XSS Bug Bounty☆192Mar 9, 2026Updated 6 months ago
- Vulnerability Research Group☆18Jul 2, 2026Updated 2 months ago
- all manner of wordlists☆24Jan 19, 2022Updated 4 years ago
- NetFuzzer is a comprehensive network security assessment tool for internal and external network components, including Host Machines, Fire…☆17Aug 4, 2025Updated last year
- This tools used for Automating finding of subdomain, and checking for alive subdomain, and gathering js files from all the subdomain and …☆23Jun 28, 2024Updated 2 years ago
- Swisscom Vulnerability Disclosure Policy & Bug Bounty Programme☆141Sep 8, 2026Updated last week
- 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages☆41Jan 31, 2026Updated 7 months ago
- burp suite插件☆14Jul 9, 2023Updated 3 years ago
- This is a python wrapper around the amazing KNOXSS API by Brute Logic☆287Mar 6, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆133Jul 15, 2021Updated 5 years ago
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 7 months ago
- Looks for parameters in urls☆35Oct 14, 2024Updated last year
- ☆200Jan 22, 2026Updated 7 months ago
- A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting☆1,910Sep 29, 2025Updated 11 months ago
- This is my personal repo, which includes bug bounty tips, a collection of tools, one-liners, and other resources I personally prefer whil…☆69Apr 25, 2025Updated last year
- ☆31Jan 19, 2026Updated 8 months ago
- ParamScan is a chrome extension for finding reflected parameters in a webpage.☆93Jan 11, 2025Updated last year
- A BurpSuite extension that allows you to use Chromium with PwnFox☆53Aug 2, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆567Mar 8, 2025Updated last year
- Top disclosed reports from HackerOne☆6,553Sep 12, 2026Updated last week
- AI-powered ffuf wrapper☆807Dec 4, 2025Updated 9 months ago
- BackupFinder discovers backup files on web servers by generating intelligent patterns.☆111Jul 29, 2025Updated last year
- Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets☆149Jan 21, 2025Updated last year
- An automated GitHub Actions-based crawler that fetches and updates public scopes from popular bug bounty platforms.☆210Apr 21, 2025Updated last year
- It serves as a practical guide for security researchers to identify and test WordPress targets effectively during bug bounty hunting.☆27Jul 19, 2026Updated 2 months ago
- Dig through the Wayback Machine and find sensitive or forgotten files exposed by web servers over time.☆31Mar 27, 2025Updated last year
- ☆13Oct 24, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A command line tool that reads from stdin and strips ANSI color codes from the input.☆10Feb 11, 2023Updated 3 years ago
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆13Aug 14, 2026Updated last month
- https://www.nu11secur1ty.com☆23Jul 1, 2026Updated 2 months ago
- List of custom Nuclei templates☆16Nov 4, 2023Updated 2 years ago
- ai-based domain name generation☆148May 7, 2026Updated 4 months ago
- An AI-powered assistant for hackers and security professionals built for Caido☆38Aug 12, 2026Updated last month
- ☆548Aug 21, 2025Updated last year