InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
-
Updated
Sep 9, 2026 - Kotlin
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses
Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.
GraphQL automated security testing toolkit
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.
GraphQL implementation based on light-4j
a vulnerable GraphQL application
A plugin based GraphQL vulnerability assessment tool.
An integrated tool to detect, fingerprint, and explore GraphQL endpoints.
Automated GraphQL pentest and fuzzing tool for bug bounty hunting and security research.
Extensión de bug bounty (Chrome/Firefox): mapea la superficie de ataque en vivo — IDOR con scoring, correlación de entidades, GraphQL, OAuth/OIDC, source maps y fingerprinting de tecnología — con cadenas de explotación sugeridas y puente a nuclei/httpx/etc.
Advanced GraphQL penetration testing checklist — covering introspection, auth bypass, injection, DoS, SSRF, subscription attacks & more. Built for security engineers & bug bounty hunters. 🔥
FortressWAF - Self-Hosted WAF & API Security Gateway. Enterprise Web Application Firewall with ML-powered threat detection, GraphQL/WebSocket/mTLS inspection, hot-reload config, SIEM export, and real-time detection. Built from scratch in Go.
Burp Suite extension for passive GraphQL reconnaissance. Catalogs operations from proxy traffic, tracks variable shapes with sample values, stores original requests per signature, and sends to Intruder with auto-marked payload positions. Supports status triage, export/import for session persistence, and batched mutation detection.
Built in the trenches—this repository captures real-world API security insights, attack techniques, and practical penetration testing workflows.
A lightweight, multi-threaded web application reconnaissance and security testing tool. Features include crawling, JavaScript analysis, secret detection, GraphQL probing, JWT analysis, security header checks, and XSS fuzzing, with JSON and HTML reporting. For authorized security testing only (MIT License)
API recon and security scanner in Rust for bug-bounty work: discovery, JS analysis, auth/GraphQL/mass-assignment checks
breach-gate
Wrapper inteligente sobre sqlmap: reconocimiento automatico de WAF/stack/ORM/GraphQL, seleccion de tampers, y deteccion propia de NoSQL injection (MongoDB). Corre 100 por ciento en Docker, sin instalar nada localmente.
To associate your repository with the graphql-security topic, visit your repo's landing page and select "manage topics."