# caido/caido

🚀 Caido releases, wiki and roadmap

Repository: https://github.com/caido/caido
Canonical: https://ross.abutalabs.com/products/caido
Homepage: https://caido.io
Language: Shell
License Family: other
Topics: security, proxy, pentesting, bugbounty, tool
Last push: 2026-08-22T16:48:13+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 1776, "days_push": 11, "days_rel": 11, "gap_med": 21.0, "n_releases_24m": 35}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2558, forks 138 (observed 2026-08-28T04:07:00.831212+00:00)

## What it is
Caido is a lightweight web security auditing toolkit and HTTP proxy for intercepting, viewing, and modifying traffic between browsers and web servers. It targets security professionals and bug bounty hunters with features like traffic interception, replay, automation workflows, HTTPQL filtering, and an extensible plugin ecosystem.

## Use cases
- intercept and modify HTTP requests between browser and server
- find vulnerabilities in web applications during pentests
- replay and iterate on requests for manual security testing
- automate batch attacks with custom payloads
- filter and search HTTP history with HTTPQL
- map endpoints and application structure with a sitemap
- extend testing workflow with community plugins
- run AI-assisted agents to draft payloads during bug bounty hunting

## When to choose
- you need a modern, fast alternative to Burp Suite for web app auditing
- you are a bug bounty hunter wanting AI-assisted and workflow-automated testing
- you want a headless, API-first proxy to build security automation on
- you want a beginner-friendly web hacking toolkit with a free tier

## When to avoid
- you need a fully open-source tool with permissive licensing - the core is proprietary with a freemium model
- you only need automated vulnerability scanning rather than manual/semi-manual testing
- you require deep mobile or non-HTTP protocol testing
- you need long-term stability guarantees - the tool ships monthly releases with evolving features

## Facets
- artifact type: application
- maturity: active
- function: proxy, security, penetration-testing, http-client, developer-tools, plugin-system, workflow-automation
- domain: security, penetration-testing, web-development, developer-tools
- platform: windows, cross-platform
- tags: web-security-auditing, http-proxy, burp-suite-alternative, bug-bounty, pentesting, websocket-interception, httpql, ai-assisted-testing, linux, macos, desktop

## Member repositories
- caido/caido (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:00.831212+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:23:37.736768+00:00, confidence not recorded.
  - readme: https://github.com/caido/caido (fetched 2026-08-28T04:07:00.831212+00:00, sha 74829ffe462d)
  - homepage: https://caido.io (fetched 2026-08-29T10:06:19.569577+00:00, sha 51e0422d7c92)
  - site_page: https://docs.caido.io/quickstart (fetched 2026-08-29T10:06:19.581059+00:00, sha 778ad5ef42f3)
  - site_page: https://www.caido.io/features (fetched 2026-08-29T10:06:19.582549+00:00, sha ca0d835c31d3)
  - site_page: https://www.caido.io/about (fetched 2026-08-29T10:06:19.584084+00:00, sha 9da5a1a3c19e)
  - site_page: https://www.caido.io/pricing (fetched 2026-08-29T10:06:19.578753+00:00, sha 285fd8daa66d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
