Customisable and automated HTTP header injection
☆271Jun 27, 2024Updated last year
Alternatives and similar repositories for headi
Users that are interested in headi are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A tool to check a bunch of URLs that contain reflecting params.☆598Aug 4, 2024Updated last year
- HTTP Request Smuggling Detection Tool☆538Dec 21, 2023Updated 2 years ago
- declutters url lists for crawling/pentesting☆1,543Feb 23, 2025Updated last year
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆303Feb 12, 2023Updated 3 years ago
- Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.☆93Jul 9, 2025Updated 9 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A fast tool to scan CRLF vulnerability written in Go☆1,529Mar 26, 2026Updated 2 weeks ago
- Open Redirection Analyzer☆811Mar 5, 2023Updated 3 years ago
- A fuzzer for detecting open redirect vulnerabilities☆784Jul 1, 2024Updated last year
- An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects☆973Dec 8, 2021Updated 4 years ago
- Automation for javascript recon in bug bounty.☆1,079Sep 9, 2023Updated 2 years ago
- A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀☆660Aug 28, 2025Updated 7 months ago
- Prototype pollution scanner using headless chrome☆217Jul 27, 2022Updated 3 years ago
- A tool to fastly get all javascript sources/files☆862Jul 4, 2025Updated 9 months ago
- Passive reconnaissance/enumeration of interesting targets by watching for SSL certificates being issued☆69Oct 11, 2022Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting with the flexibility to host WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Cloudways by DigitalOcean.
- A tool for append URLs, skipping duplicates/paths & combine parameters.☆128Mar 2, 2022Updated 4 years ago
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆295Sep 22, 2024Updated last year
- Automating XSS using Bash☆363Jan 27, 2026Updated 2 months ago
- ☆57Sep 2, 2020Updated 5 years ago
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,067Jan 2, 2024Updated 2 years ago
- A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.☆518Jun 22, 2022Updated 3 years ago
- Scrape domain names from SSL certificates of arbitrary hosts☆690Mar 31, 2024Updated 2 years ago
- Secret and/or credential patterns used for gf.☆243Feb 10, 2023Updated 3 years ago
- Find endpoints on GitHub.☆219Mar 28, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,095Apr 3, 2026Updated last week
- A tool to find redirection chains in multiple URLs☆78Jan 1, 2025Updated last year
- CloudFlare Checker written in Go☆236May 12, 2024Updated last year
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆156Nov 24, 2023Updated 2 years ago
- A fast DOM based XSS vulnerability scanner with simplicity.☆856Sep 30, 2022Updated 3 years ago
- The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.☆1,287Feb 10, 2026Updated 2 months ago
- ☆59Apr 8, 2021Updated 5 years ago
- Hidden parameters discovery suite☆2,044Sep 8, 2024Updated last year
- Command line tool for testing CRLF injection on a list of domains.☆163Apr 14, 2024Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities☆127Jun 4, 2023Updated 2 years ago
- Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hac…☆1,169Jan 21, 2026Updated 2 months ago
- Heuristic Vulnerable Parameter Scanner☆602Jan 8, 2024Updated 2 years ago
- CORS Misconfiguration Scanner☆1,513Sep 17, 2022Updated 3 years ago
- SSRF plugin for burp Automates SSRF Detection in all of the Request☆620Jan 20, 2021Updated 5 years ago
- Web App bug hunting☆576Nov 26, 2025Updated 4 months ago
- XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|ID…☆351Jun 17, 2023Updated 2 years ago