# almandin/fuxploider

File upload vulnerability scanner and exploitation tool.

Repository: https://github.com/almandin/fuxploider
Canonical: https://ross.abutalabs.com/products/fuxploider
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: python3, pentesting, exploitation, takeover, vulnerability-scanner, detection
Last push: 2025-05-08T09:00:36+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 20, release rhythm 8, longevity 100
- inputs: {"age_days": 3337, "days_push": 482, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3328, forks 509 (observed 2026-08-28T04:07:56.504277+00:00)

## What it is
Fuxploider is an open-source penetration testing tool that automates detection and exploitation of file upload form vulnerabilities. It identifies allowed file types and determines the best technique to upload web shells or malicious files to a target web server.

## Use cases
- scan a website for file upload vulnerabilities
- test if a file upload form allows web shell uploads
- find which file types an upload endpoint accepts
- automate pentesting of file upload forms
- detect exploitable upload forms during a security assessment

## When to choose
- you are doing authorized penetration testing on web apps with upload forms
- you need to automate detection of file upload flaws and shell upload techniques

## When to avoid
- you lack explicit permission to test the target (illegal use)
- you need a general-purpose web vulnerability scanner beyond upload flaws

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, vulnerability-scanning, security
- domain: security, penetration-testing, web-development
- platform: python, cli, windows
- tags: file-upload, web-shell, pentesting, exploitation, web-security, linux, macos, docker

## Member repositories
- almandin/fuxploider (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:56.504277+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:41:45.183180+00:00, confidence not recorded.
  - readme: https://github.com/almandin/fuxploider (fetched 2026-08-28T04:07:56.504277+00:00, sha 213f15e5dfe7)
- Data as of 2026-08-30T08:39:29.467469+00:00.
