Ross ROSS = Recommend OSS · open-source software intelligence for agents

lijiejie/BBScan

A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers observed · 2026-08-28

github.com/lijiejie/BBScan · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3946
  • days_rel: n/a
  • days_push: 610
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2371 stars · 582 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

BBScan is a fast, lightweight, high-concurrency web vulnerability scanner written in Python. It helps penetration testers quickly identify potentially vulnerable targets from large numbers of web servers by detecting data leaks, directory traversal, admin backends, token/secret leaks, and web fingerprints.

Use cases

  • scan a large list of web servers for common vulnerabilities
  • find exposed git and svn directories on web targets
  • detect leaked tokens, secrets, passwords, and API keys in JavaScript files
  • extract API endpoints from .js files of a website
  • identify web frameworks, CMS, and middleware fingerprints of targets
  • scan neighbor hosts in the same network subnet
  • generate HTML scan reports for a batch of domains

When to choose

  • you need to quickly triage many web targets for obvious weaknesses during a pentest
  • you want a lightweight Python-based scanner without heavy dependencies
  • you need combined vulnerability checks and web fingerprinting in one tool

When to avoid

  • you need deep exploitation capabilities rather than detection
  • you require a full-featured scanner with extensive plugin ecosystems like Burp Suite or Nuclei templates
  • you need authenticated or complex multi-step application testing

Facets

cli-tool · maturity active

security vulnerability-scanning web-scraping cli security penetration-testing web-development python cli windows vulnerability-scanner pentesting web-security fingerprinting secret-detection directory-traversal api-endpoint-discovery command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
lijiejie/BBScanmain23

For agents

markdown · JSON · MCP: product_card(name="lijiejie/BBScan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem