csp-auditor

Security auditor

Analyzes and configures website security policies to prevent malicious scripts from running on user devices.

Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

GitHub

138 stars
12 watching
34 forks
Language: Java
last commit: over 6 years ago
Linked from 1 awesome list

burpburp-plugincsphacktoberfesthttpsecurityzapzap-plugin

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
moloch--/csp-bypassDetects vulnerabilities in Content Security Policies163
malerisch/burp-csjAn extension for Burp Pro that integrates Crawljax and Selenium with JUnit for web application security testing and crawling.33
contrast-security-oss/burptrastAutomates vulnerability assessment and endpoint discovery for web applications using Contrast Security's Teamserver API.16
secdec/attack-surface-detector-burpIdentifies web app endpoints and parameters to help detect vulnerabilities98
gosecure/burp-fuzzy-encoding-generatorTools to test various encoding options in Burp Intruder attacks6
zigoo0/jsonbeeAutomated tool to discover and generate bypass payloads for Content Security Policy (CSP) restrictions on web pages678
w3c/webappsec-cspA specification and implementation of the Content Security Policy (CSP) standard to secure web applications210
seisvelas/san-scannerAn extension for Burp Suite that helps discover Subject Alt Names in SSL certificates3
gand3lf/semgrepperAn extension to Burp Suite that integrates Semgrep for vulnerability scanning and analysis88
debasishm89/burpyA tool that analyzes web application security by parsing Burp Suite logs and generating reports.120
boostsecurityio/poutineDetects misconfigurations and vulnerabilities in software supply chains during build pipelines.239
peachtech/peachapisec-burpA tool for integrating automated security testing with web API analysis in Burp Suite2
unstppbl/gowapAnalyzes web pages to extract technologies and metadata193
govtech-csg/autowaspA tool to automate web security testing and logging using Burp Suite75
zimmski/go-mutestingA tool to detect untested parts of source code by introducing small changes and testing the resulting behavior.650