All tags
Catalogue tag

#bug-bounty

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

19 records
Tagged “bug-bounty”Ranked by health index
npm
91Excellenthealth index
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
AGPL-3.0Jul 23, 2026 · metrics 2.10.0
PyPI
91Excellenthealth index
usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · Go · TypeScript★ 48.3KAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
Go · npm
83Excellenthealth index
xalgord/xalgorix
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Go · TypeScript★ 768Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
PyPI · crates.io
78Goodhealth index
maurosoria/dirsearch
Web path scanner
Python★ 14.6K↓ 32.4K/moAug 19, 2026
No licenseAug 19, 2026 · metrics 2.10.0
Go
75Goodhealth index
Chocapikk/wpprobe
A fast WordPress plugin enumeration tool
Go★ 937Aug 29, 2026
MITAug 29, 2026 · metrics 2.10.0
Go
73Goodhealth index
zan8in/afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.
Go · HTML★ 4,371Aug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
Go
71Goodhealth index
vigolium/vigolium
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Go★ 826Jul 15, 2026
Custom licenseJul 15, 2026 · metrics 2.10.0
Go
67Goodhealth index
cc1a2b/JShunter
jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for and bug bounty hunters and security researchers.
Go★ 533Sep 6, 2026
MITSep 6, 2026 · metrics 2.10.0
53Moderatehealth index
0xSteph/pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Shell★ 2,067Aug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
53Moderatehealth index
momenbasel/keyFinder
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
JavaScript · HTML · CSS★ 693Jul 27, 2026
MITJul 27, 2026 · metrics 2.10.0
npm
51Moderatehealth index
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 463Jul 19, 2026
AGPL-3.0Jul 19, 2026 · metrics 2.10.0
Go
51Moderatehealth index
dinosn/leaklens
Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery
Go★ 58Aug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
Go
38Weakhealth index
11lunaric11/securitychecker
Recon tool for pentesters & bug bounty hunters: check robots.txt, security.txt (RFC 9116) and /.well-known/ across many targets. CLI + web UI, single static Go binary.
Go · HTML★ 2Jul 18, 2026
MITJul 18, 2026 · metrics 2.10.0
PyPI
31At Riskhealth index
aaaguirrep/offensive-docker
Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.
Dockerfile★ 767Aug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
Go
31At Riskhealth index
mehulgupta1/subhound
Advanced subdomain enumeration for Linux & macOS — one Go binary that orchestrates subfinder, dnsx, httpx, asnmap & more into a fast discover→resolve→probe pipeline.
Go★ 1Aug 20, 2026
No licenseAug 20, 2026 · metrics 2.10.0
npm
21At Riskhealth index
LasCC/HackTools
The all-in-one browser extension for offensive security professionals 🛠
TypeScript★ 6,943Aug 4, 2026
No licenseAug 4, 2026 · metrics 2.10.0
Go
19Criticalhealth index
ps1-blacklist/wpfather
WPFather - WordPress Vulnerability Scanner & Security Recon Tool with 16 Modules | Zero Config Single Binary
Go★ 0Jul 16, 2026
Custom licenseJul 16, 2026 · metrics 2.10.0
npm
19Criticalhealth index
xaccefy/pi-xpi
XPI — offensive security tools for Pi Agent: casefile, exploit search, web lookup, code intelligence, todo tracker
TypeScript★ 14↓ 2,871/moSep 6, 2026
MITSep 6, 2026 · metrics 2.10.0