# fin3ss3g0d/evilgophish

evilginx3 + gophish

Repository: https://github.com/fin3ss3g0d/evilgophish
Canonical: https://ross.abutalabs.com/products/evilgophish
Language: Go
License: MIT
License Family: permissive
Last push: 2024-06-15T17:48:11+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1456, "days_push": 809, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2022, forks 377 (observed 2026-08-28T04:06:06.500717+00:00)

## What it is
evilgophish is a Go-based framework combining evilginx3 and GoPhish for running authorized phishing and smishing campaigns with real-time credential capture and session cookie harvesting. It supports email and SMS campaigns, tracking, QR code generation, and live campaign feeds.

## Use cases
- run authorized phishing awareness campaigns
- capture credentials and session cookies in red team engagements
- set up smishing (SMS phishing) campaigns
- simulate phishing with tracking pixels and campaign analytics
- host reverse-proxy phishing pages behind a real domain

## When to choose
- you need evilginx-style session hijacking integrated with GoPhish campaign management
- you are a red teamer or pentester with written authorization to test social engineering
- you want combined email and SMS phishing simulation infrastructure

## When to avoid
- you lack explicit written authorization for phishing engagements
- you need a fully supported, up-to-date tool - the public version lags the sponsor-only version
- you only need simple email security awareness training without reverse-proxy capture

## Facets
- artifact type: application
- maturity: maintenance
- function: security, penetration-testing, http-server, email, webhook
- domain: security, penetration-testing
- platform: go, self-hosted
- tags: phishing-simulation, red-team, social-engineering, evilginx, gophish, credential-harvesting, session-hijacking, smishing, linux

## Member repositories
- fin3ss3g0d/evilgophish (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:06.500717+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:00:06.049356+00:00, confidence not recorded.
  - readme: https://github.com/fin3ss3g0d/evilgophish (fetched 2026-08-28T04:06:06.500717+00:00, sha 77624f16e05c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
