Shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Filament plugins, Laravel packages and open source starter kits actively maintained. All MIT, with releases for v3, v4 and v5 where applicable.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Find secrets with Gitleaks 🔑
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
☠️ A production-grade autonomous penetration testing platform that automates deep reconnaissance, machine learning-driven risk scoring, verified exploitation, and compliance reporting. Features 205 modules, an async task graph orchestrator, and automated threat mapping to MITRE ATT&CK and OWASP Top 10.
Cerebro runtime, public applications, contracts, and SDKs
All packages have CI, Pest tests and open issues tagged good first issue.
New version available.