Customisable and automated HTTP header injection
☆293Jun 27, 2024Updated last year
Alternatives and similar repositories for headi
Users that are interested in headi are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A tool to check a bunch of URLs that contain reflecting params.☆600Aug 4, 2024Updated last year
- HTTP Request Smuggling Detection Tool☆539Dec 21, 2023Updated 2 years ago
- declutters url lists for crawling/pentesting☆1,558Feb 23, 2025Updated last year
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆301Feb 12, 2023Updated 3 years ago
- Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.☆93Jul 9, 2025Updated 11 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A fast tool to scan CRLF vulnerability written in Go☆1,540May 22, 2026Updated 2 weeks ago
- Open Redirection Analyzer☆812Mar 5, 2023Updated 3 years ago
- An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects☆972Dec 8, 2021Updated 4 years ago
- A fuzzer for detecting open redirect vulnerabilities☆789Jul 1, 2024Updated last year
- Automation for javascript recon in bug bounty.☆1,089Sep 9, 2023Updated 2 years ago
- A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀☆667Aug 28, 2025Updated 9 months ago
- Prototype pollution scanner using headless chrome☆216Jul 27, 2022Updated 3 years ago
- A tool to fastly get all javascript sources/files☆881Jul 4, 2025Updated 11 months ago
- Passive reconnaissance/enumeration of interesting targets by watching for SSL certificates being issued☆67Oct 11, 2022Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A tool for append URLs, skipping duplicates/paths & combine parameters.☆129Mar 2, 2022Updated 4 years ago
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆296Sep 22, 2024Updated last year
- Automating XSS using Bash☆365Jan 27, 2026Updated 4 months ago
- ☆57Sep 2, 2020Updated 5 years ago
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,077Jan 2, 2024Updated 2 years ago
- A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.☆519Jun 22, 2022Updated 3 years ago
- Scrape domain names from SSL certificates of arbitrary hosts☆691Mar 31, 2024Updated 2 years ago
- Secret and/or credential patterns used for gf.☆245Feb 10, 2023Updated 3 years ago
- Find endpoints on GitHub.☆219Mar 28, 2023Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,173Apr 3, 2026Updated 2 months ago
- A tool to find redirection chains in multiple URLs☆79Jan 1, 2025Updated last year
- Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hac…☆1,176Jan 21, 2026Updated 4 months ago
- CloudFlare Checker written in Go☆238May 12, 2024Updated 2 years ago
- The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.☆1,291Jun 1, 2026Updated last week
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆158Nov 24, 2023Updated 2 years ago
- Hidden parameters discovery suite☆2,064Sep 8, 2024Updated last year
- A fast DOM based XSS vulnerability scanner with simplicity.☆862Sep 30, 2022Updated 3 years ago
- ☆59Apr 8, 2021Updated 5 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Heuristic Vulnerable Parameter Scanner☆604Jan 8, 2024Updated 2 years ago
- Command line tool for testing CRLF injection on a list of domains.☆163Apr 14, 2024Updated 2 years ago
- Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities☆127Jun 4, 2023Updated 3 years ago
- CORS Misconfiguration Scanner☆1,521Sep 17, 2022Updated 3 years ago
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep☆1,433Sep 13, 2024Updated last year
- SSRF plugin for burp Automates SSRF Detection in all of the Request☆626Jan 20, 2021Updated 5 years ago
- Web App bug hunting☆578Nov 26, 2025Updated 6 months ago