laluka/bypass-url-parser
bypass-url-parser observed · 2026-08-28
Health v2 · maintenance only
74/100
- Activity 99
- Release rhythm 28
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 44
- age_days: 1769
- days_rel: 679
- days_push: 11
- n_releases_24m: 2
Adoption not part of the score
1138 stars · 122 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Python CLI tool (usable as a library) that generates and tests many URL bypass payloads to access 40X-protected pages, using curl as its backend to avoid unwanted URL normalization. It supports raw HTTP requests, header spoofing, proxies, threading, and JSONL output.
Use cases
- bypass 403 forbidden pages on a web app
- test url parsing differential bypasses during a pentest
- find ways to reach a protected endpoint
- test ip header spoofing bypasses against a url
- generate url bypass payloads from a raw http request
When to choose
- you need raw, non-normalized URL payloads sent exactly as written
- you want a quick CLI to enumerate many 40X bypass techniques
- you need a Python library for programmatic URL bypass testing
When to avoid
- you need a general-purpose web vulnerability scanner
- you want a GUI or non-technical workflow
- you only need standard HTTP requests without bypass payloads
Facets
cli-tool · maturity active
parser http-client security penetration-testing cli security penetration-testing web-development python cli windows cross-platform url-bypass 40x-bypass curl-wrapper offensive-security differential-testing pentest-tool command-line linux macos
2 sources
- readme: https://github.com/laluka/bypass-url-parser · fetched 2026-08-28 · d4663cb767c9
- registry_pypi: https://pypi.org/pypi/bypass-url-parser/json · fetched 2026-08-29 · 8c2cb9f88dec
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| laluka/bypass-url-parser | main | 74 |
For agents
markdown · JSON · MCP: product_card(name="laluka/bypass-url-parser")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem