Skip to content
OpenCatalogcurated by FLOSSK

Browse & filter

Filter by platform, license text, maturity, maintenance cadence, and editorial tags like privacy-focused or self-hosted. Search matches names, summaries, tags, and use cases.

14 tools match your filters

Honorable mention

MIT-licensed web-technology editor focused on HTML/CSS/JS with live preview roots.

editorwebhtml

OWASP flagship web app scanner and proxy: automated checks, manual request tampering, scripting, and CI integrations.

pentestwebdastowaspproxy

Automatic SQL injection and database takeover helper with fingerprinting, data exfiltration, and OS-shell paths.

pentestwebsqlipython

Web server scanner that probes for dangerous files, outdated software, and misconfigurations via many checks.

pentestwebscannerrecon

Fast web fuzzer for directories, virtual hosts, parameters, and raw HTTP—common in bug bounty playbooks.

pentestwebfuzzingdiscovery

Go-based directory/DNS/vhost brute-forcer with threading tuned for pentest wordlists.

pentestwebbrute-forcego

Recursive content discovery written in Rust with intelligent filtering and replay-friendly output.

pentestwebrustdiscovery

WordPress security scanner: version fingerprinting, plugin/theme vuln DB, weak creds, and user enumeration.

pentestwebwordpresscms
Honorable mention

XSS parameter analyzer and reflected/stored/DOM-focused fuzzer with mining and pipeline modes.

pentestwebxssgo

Web application firewall engine for Apache, nginx, and IIS with OWASP CRS rule sets and audit logging.

wafwebowaspreverse-proxy
Honorable mention

Web-based SVG editor for quick vector tweaks, diagram polish, and embedding in self-hosted pages.

svgwebvectorbrowser