# wagiro/BurpBounty

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.

Repository: https://github.com/wagiro/BurpBounty
Canonical: https://ross.abutalabs.com/products/burpbounty
Language: Java
License: Apache-2.0
License Family: permissive
Topics: bugbounty, burp-extensions, burpsuite, bug-bounty, vulnerability-scanner, vulnerability-detection
Last push: 2024-04-26T01:17:17+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3017, "days_push": 860, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1809, forks 335 (observed 2026-08-28T04:05:39.426029+00:00)

## What it is
Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners with custom rules through a graphical interface. Users define pattern searches and payloads to create their own issue profiles for detecting web vulnerabilities.

## Use cases
- create custom active and passive scan rules in Burp Suite
- detect web vulnerabilities with personalized scanner profiles
- find blind RCE using Burp Collaborator payloads
- improve bug bounty hunting with tailored scan checks
- share and reuse community vulnerability detection profiles
- run pattern-based payload scanning during manual pentests

## When to choose
- you use Burp Suite and want to extend its scanner without writing Java code
- you need custom active/passive scan rules with a GUI instead of scripting
- you want community-maintained profiles for common web vulnerabilities
- you do bug bounty or manual pentesting and need targeted issue detection

## When to avoid
- you need a standalone vulnerability scanner outside Burp Suite
- you want fully automated continuous scanning pipelines rather than manual pentest support
- you need the advanced automation features reserved for Burp Bounty Pro

## Facets
- artifact type: plugin
- maturity: active
- function: vulnerability-scanning, security, penetration-testing, plugin-system
- domain: security, penetration-testing, developer-tools
- platform: jvm, cross-platform
- tags: burp-suite, burp-extension, bug-bounty, web-security-scanning, custom-scanner-rules, active-scanning, passive-scanning, desktop

## Member repositories
- wagiro/BurpBounty (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:39.426029+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:21:20.957181+00:00, confidence not recorded.
  - readme: https://github.com/wagiro/BurpBounty (fetched 2026-08-28T04:05:39.426029+00:00, sha fcf6a63eae56)
- Data as of 2026-08-30T08:39:29.467469+00:00.
