This is a collection of sites about security.
The order is alphabetical.

Show Search Menu
URL
Name
Language
Number of items displayed
framework
No Image Name URL Description Tag
1 Acunetix https://www.acunetix.com/ A commercial web application security scanner that helps detect vulnerabilities like SQL injection, XSS, and other web app-specific issues. It offers automated scans and manual testing features.sss
  • English
  • Web Audit
  • FW Audit
2 Arachni https://ecsypno.com/pages/arachni-web-application-security-scanner-framework An open-source, high-performance security scanner for web applications. It’s designed for flexibility and can scan for vulnerabilities like XSS, SQL injection, and remote file inclusion.sss
  • English
  • Web Audit
  • Tools
  • Open Source
3 Burp Suite https://portswigger.net/burp A powerful integrated platform for web application security testing. It provides tools for crawling, scanning, and analyzing web applications to identify vulnerabilities like SQL injection, XSS, and more.sss
  • English
  • Web Audit
  • Tools
  • Hacking
4 Gophish https://getgophish.com/ This is an open source phishing framework. It is the perfect tool if you want to conduct targeted email training and education on phishing within your company without incurring any costs.sss
  • Japanese
  • Tools
  • Targeted Email Attack Training
  • Social engineering
5 IronWASP https://sboxr.com A web application security testing platform with a user-friendly GUI. It offers various plugins to help identify and fix security issues in web applications.sss
  • English
  • Web Audit
  • Tools
6 Nikto https://cirt.net/Nikto2 A web server scanner that identifies potential security issues and vulnerabilities in web applications, such as outdated software and configuration flaws.sss
  • English
  • Web Audit
  • Tools
7 OWASP ZAP (Zed Attack Proxy) https://www.zaproxy.org/ An open-source security testing tool developed by OWASP. It is used for finding security vulnerabilities in web applications during the development and testing phases.sss
  • English
  • Web Audit
  • Tools
  • Hacking
8 Samurai Web Testing Framework http://www.samurai-wtf.org/ Web penetration testing virtual machine built on open source software.sss
  • English
  • Tools
  • Open Source
9 Selenium https://www.selenium.dev/ A popular framework for automating web browsers. While it’s mainly used for testing the functionality of web applications, it can also be used for security testing by simulating attack patterns.sss
  • English
  • Tools
  • Open Source
10 Skipfish https://code.google.com/archive/p/skipfish/ A fast, automated web application security scanner. It uses a lightweight approach to discover vulnerabilities and generate detailed reports.sss
  • English
  • Web Audit
  • Tools
11 w3af http://docs.w3af.org/en/latest/index.html w3af is a complete environment for auditing and exploiting Web applications. This environment provides a solid platform for web vulnerability assessments and penetration tests.sss
  • English
  • Web Audit
  • Tools
12 Wapiti https://wapiti.sourceforge.io/ An open-source web application scanner that performs black-box testing to identify vulnerabilities, including SQL injection, XSS, and file disclosure vulnerabilities.sss
  • English
  • Web Audit
  • Tools
  • Open Source
13 WebScarab https://wiki.owasp.org/index.php/Category:OWASP_WebScarab_Project An open-source framework for web application analysis and penetration testing. It allows for intercepting and analyzing HTTP/HTTPS traffic and discovering vulnerabilities.sss
  • English
  • Web Audit
  • Tools
  • Open Source