chainreactors/spray
最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer. observed · 2026-08-28
Health v2 · maintenance only
93/100
- Activity 93
- Release rhythm 90
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 21.0
- age_days: 1455
- days_rel: 65
- days_push: 45
- n_releases_24m: 15
Adoption not part of the score
1058 stars · 72 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Spray is a high-performance HTTP directory fuzzing and content discovery tool written in Go, positioned as a next-generation alternative to feroxbuster, ffuf, and dirsearch. It combines directory bruteforcing with mask/rule-based wordlist generation, intelligent dynamic filtering, web fingerprinting, sensitive information extraction, and resume support.
Use cases
- bruteforce hidden directories and files on a web server
- generate wordlists with masks and hashcat-style rules
- fingerprint web technologies during reconnaissance
- scan for backup files and common sensitive files
- bulk scan multiple URLs for interesting paths
- resume an interrupted directory scan
- detect WAF blocking and bans during fuzzing
When to choose
- you need faster directory bruteforcing than ffuf or feroxbuster, especially across many targets
- you want built-in fingerprinting, crawling, and backup-file discovery in one tool
- you need mask- or rule-based dictionary generation instead of static wordlists
- you want smart automatic filtering of invalid pages with fine-grained control
When to avoid
- you need a general-purpose HTTP parameter fuzzing tool with complex payload injection (use ffuf)
- you only need a simple, minimal directory scanner with a small feature set
- you require a GUI-driven scanning workflow
- you need a distributed scanning solution today (cloud/distribution features are still on the roadmap)
Facets
cli-tool · maturity active
security web-scraping http-client cli developer-tools security penetration-testing web-development windows cli go directory-bruteforce content-discovery http-fuzzing fingerprinting red-team wordlist-generation waf-detection command-line linux macos
10 sources
- readme: https://github.com/chainreactors/spray · fetched 2026-08-28 · 32f874104605
- homepage: https://chainreactors.github.io/wiki/spray/ · fetched 2026-08-29 · 23296d5b0afb
- site_page: https://wiki.chainreactors.red/IoM/getting-started · fetched 2026-08-29 · d505cd303139
- site_page: https://wiki.chainreactors.red/IoM/getting-started/concepts · fetched 2026-08-29 · 1f963ba08c60
- site_page: https://wiki.chainreactors.red/IoM/getting-started/design · fetched 2026-08-29 · 7741cdba9ce1
- site_page: https://wiki.chainreactors.red/IoM/getting-started/roadmap · fetched 2026-08-29 · 8758eccc1a07
- site_page: https://wiki.chainreactors.red/IoM/user-guide/client-quickstart · fetched 2026-08-29 · d51ca7e7c06f
- site_page: https://wiki.chainreactors.red/IoM/development/mals/quickstart · fetched 2026-08-29 · 868defb49d3f
- site_page: https://wiki.chainreactors.red/malefic/getting-started · fetched 2026-08-29 · 529a7d141f18
- site_page: https://wiki.chainreactors.red/malefic/getting-started/architecture · fetched 2026-08-29 · 72cb7cbd407c
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| chainreactors/spray | main | 93 |
For agents
markdown · JSON · MCP: product_card(name="chainreactors/spray")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem