Ross ROSS = Recommend OSS · open-source software intelligence for agents

caido/caido

🚀 Caido releases, wiki and roadmap observed · 2026-08-28

github.com/caido/caido · homepage · Shell observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 99
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 21.0
  • age_days: 1776
  • days_rel: 11
  • days_push: 11
  • n_releases_24m: 35

Full methodology

Adoption not part of the score

2558 stars · 138 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Caido is a lightweight web security auditing toolkit and HTTP proxy for intercepting, viewing, and modifying traffic between browsers and web servers. It targets security professionals and bug bounty hunters with features like traffic interception, replay, automation workflows, HTTPQL filtering, and an extensible plugin ecosystem.

Use cases

  • intercept and modify HTTP requests between browser and server
  • find vulnerabilities in web applications during pentests
  • replay and iterate on requests for manual security testing
  • automate batch attacks with custom payloads
  • filter and search HTTP history with HTTPQL
  • map endpoints and application structure with a sitemap
  • extend testing workflow with community plugins
  • run AI-assisted agents to draft payloads during bug bounty hunting

When to choose

  • you need a modern, fast alternative to Burp Suite for web app auditing
  • you are a bug bounty hunter wanting AI-assisted and workflow-automated testing
  • you want a headless, API-first proxy to build security automation on
  • you want a beginner-friendly web hacking toolkit with a free tier

When to avoid

  • you need a fully open-source tool with permissive licensing - the core is proprietary with a freemium model
  • you only need automated vulnerability scanning rather than manual/semi-manual testing
  • you require deep mobile or non-HTTP protocol testing
  • you need long-term stability guarantees - the tool ships monthly releases with evolving features

Facets

application · maturity active

proxy security penetration-testing http-client developer-tools plugin-system workflow-automation security penetration-testing web-development developer-tools windows cross-platform web-security-auditing http-proxy burp-suite-alternative bug-bounty pentesting websocket-interception httpql ai-assisted-testing linux macos desktop

6 sources

Member repositories

RepositoryRoleHealth v2
caido/caidomain99

For agents

markdown · JSON · MCP: product_card(name="caido/caido")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem