# anouarbensaad/vulnx

vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning.

Repository: https://github.com/anouarbensaad/vulnx
Canonical: https://ross.abutalabs.com/products/anouarbensaad-vulnx
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: crawler, information-gathering, cms-detector, cloudflare-detection, bot, pentest, wp-scanner, auto-exploiter, vulnerability, hacking, website-vulnerability-scanner, security-tools, vulnerability-assessment, vulnerability-exploit, vulnerability-detection, shell-injection, detects-vulnerabilities, exploits, dorks, subdomains-gathering
Last push: 2023-06-07T05:13:46+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2932, "days_push": 1183, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2138, forks 361 (observed 2026-08-28T04:06:18.063864+00:00)

## What it is
VulnX is a Python CLI tool that detects CMS types (WordPress, Joomla, Drupal, etc.), gathers target information like subdomains and DNS records, and scans websites for known vulnerabilities. It can automatically inject shells into vulnerable targets and search for exploitable URLs via dorks.

## Use cases
- scan a website for cms vulnerabilities
- detect what cms a site is running
- gather subdomains and dns info for a target domain
- find exploitable urls with google dorks
- automatically inject a shell into a vulnerable cms
- run a pentest recon on multiple websites

## When to choose
- you need automated cms detection and vulnerability scanning from the command line
- you want subdomain and dns reconnaissance bundled with vuln scanning
- you're doing authorized penetration testing on cms-based sites

## When to avoid
- you need a maintained tool with active development and recent updates
- you require a full-featured commercial-grade vulnerability scanner
- you lack authorization to test the target systems - using this on sites you don't own is illegal

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: vulnerability-scanning, web-scraping, security, osint, cli
- domain: security, penetration-testing, crawlers, web-development
- platform: windows, python, cli
- tags: cms-detector, auto-exploiter, shell-injection, subdomain-enumeration, dork-search, pentesting, wordpress-scanner, linux, macos

## Member repositories
- anouarbensaad/vulnx (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:18.063864+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:51:35.788547+00:00, confidence not recorded.
  - readme: https://github.com/anouarbensaad/vulnx (fetched 2026-08-28T04:06:18.063864+00:00, sha 0a56491c796e)
  - registry_pypi: https://pypi.org/pypi/vulnx/json (fetched 2026-08-29T10:31:35.062191+00:00, sha 5b44c3104b06)
- Data as of 2026-08-30T08:39:29.467469+00:00.
