# Karanxa/Bug-Bounty-Wordlists

A repository that includes all the important wordlists used while bug hunting.

Repository: https://github.com/Karanxa/Bug-Bounty-Wordlists
Canonical: https://ross.abutalabs.com/products/bug-bounty-wordlists
Homepage: https://twitter.com/Itskaranxa
License: MIT
License Family: permissive
Topics: hacktoberfest, bugbounty, hacktoberfest2022
Last push: 2023-03-11T12:49:01+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1906, "days_push": 1271, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1429, forks 366 (observed 2026-08-28T04:04:42.145241+00:00)

## What it is
A curated collection of wordlists commonly used during bug bounty hunting and web security testing, aggregated from public sources into one repository. It is a data resource rather than a tool, MIT-licensed and community-contributed.

## Use cases
- find wordlists for bug bounty hunting
- get directory brute-force lists for web fuzzing
- collect subdomain enumeration wordlists
- gather payload lists for security testing
- download curated recon wordlists in one place

## When to choose
- you need ready-made wordlists for tools like ffuf, gobuster, or dirsearch
- you want a single aggregated collection of public bug bounty wordlists
- you are doing bug bounty recon or web application fuzzing

## When to avoid
- you need actively maintained or frequently updated wordlists
- you need a scanning or fuzzing tool rather than raw wordlist data
- you require wordlists with verified provenance or licensing for each source

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, penetration-testing, osint, developer-tools
- domain: security, penetration-testing, developer-tools
- platform: cross-platform, cli
- tags: bug-bounty, wordlists, fuzzing, recon, security-testing, curated-list

## Member repositories
- Karanxa/Bug-Bounty-Wordlists (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:42.145241+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:37:13.924667+00:00, confidence not recorded.
  - readme: https://github.com/Karanxa/Bug-Bounty-Wordlists (fetched 2026-08-28T04:04:42.145241+00:00, sha 2cdd0690f0ef)
- Data as of 2026-08-30T08:39:29.467469+00:00.
