Ross ROSS = Recommend OSS · open-source software intelligence for agents

chainreactors/spray

最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer. observed · 2026-08-28

github.com/chainreactors/spray · homepage · Go · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

93/100

  • Activity 93
  • Release rhythm 90
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 21.0
  • age_days: 1455
  • days_rel: 65
  • days_push: 45
  • n_releases_24m: 15

Full methodology

Adoption not part of the score

1058 stars · 72 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Spray is a high-performance HTTP directory fuzzing and content discovery tool written in Go, positioned as a next-generation alternative to feroxbuster, ffuf, and dirsearch. It combines directory bruteforcing with mask/rule-based wordlist generation, intelligent dynamic filtering, web fingerprinting, sensitive information extraction, and resume support.

Use cases

  • bruteforce hidden directories and files on a web server
  • generate wordlists with masks and hashcat-style rules
  • fingerprint web technologies during reconnaissance
  • scan for backup files and common sensitive files
  • bulk scan multiple URLs for interesting paths
  • resume an interrupted directory scan
  • detect WAF blocking and bans during fuzzing

When to choose

  • you need faster directory bruteforcing than ffuf or feroxbuster, especially across many targets
  • you want built-in fingerprinting, crawling, and backup-file discovery in one tool
  • you need mask- or rule-based dictionary generation instead of static wordlists
  • you want smart automatic filtering of invalid pages with fine-grained control

When to avoid

  • you need a general-purpose HTTP parameter fuzzing tool with complex payload injection (use ffuf)
  • you only need a simple, minimal directory scanner with a small feature set
  • you require a GUI-driven scanning workflow
  • you need a distributed scanning solution today (cloud/distribution features are still on the roadmap)

Facets

cli-tool · maturity active

security web-scraping http-client cli developer-tools security penetration-testing web-development windows cli go directory-bruteforce content-discovery http-fuzzing fingerprinting red-team wordlist-generation waf-detection command-line linux macos

10 sources

Member repositories

RepositoryRoleHealth v2
chainreactors/spraymain93

For agents

markdown · JSON · MCP: product_card(name="chainreactors/spray")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem