An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses
-
Updated
Jul 31, 2025 - Go
An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.
GraphQL automated security testing toolkit
AI-native security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.
GraphQL implementation based on light-4j
a vulnerable GraphQL application
A plugin based GraphQL vulnerability assessment tool.
Automated GraphQL pentest and fuzzing tool for bug bounty hunting and security research.
An integrated tool to detect, fingerprint, and explore GraphQL endpoints.
FortressWAF - Self-Hosted WAF & API Security Gateway. Enterprise Web Application Firewall with ML-powered threat detection, GraphQL/WebSocket/mTLS inspection, hot-reload config, SIEM export, and real-time detection. Built from scratch in Go.
Burp Suite extension for passive GraphQL reconnaissance. Catalogs operations from proxy traffic, tracks variable shapes with sample values, stores original requests per signature, and sends to Intruder with auto-marked payload positions. Supports status triage, export/import for session persistence, and batched mutation detection.
A lightweight, multi-threaded web application reconnaissance and security testing tool. Features include crawling, JavaScript analysis, secret detection, GraphQL probing, JWT analysis, security header checks, and XSS fuzzing, with JSON and HTML reporting. For authorized security testing only (MIT License)
Advanced GraphQL penetration testing checklist — covering introspection, auth bypass, injection, DoS, SSRF, subscription attacks & more. Built for security engineers & bug bounty hunters. 🔥
Extract GraphQL schema from Android APKs — when introspection is disabled
Black-box pentest + architecture auditor for Supabase. Real attacks against RLS, RPC, storage, GraphQL, Realtime, JWT, edge functions — not pattern matching.
Complete guide for learning SQLi vulnerabilities across databases.
Comprehensive GraphQL security scanner and runtime shield
breach-gate
Add a description, image, and links to the graphql-security topic page so that developers can more easily learn about it.
To associate your repository with the graphql-security topic, visit your repo's landing page and select "manage topics."