# TheKingOfDuck/fuzzDicts

You Know, For WEB Fuzzing !

Repository: https://github.com/TheKingOfDuck/fuzzDicts
Canonical: https://ross.abutalabs.com/products/fuzzdicts
Language: Python
License Family: other
Topics: fuzzing, fuzz-testing, pentesting, username, password, directory, paramter, wfuzz, fuzzer
Last push: 2023-11-13T03:48:29+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2664, "days_push": 1024, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 8422, forks 2474 (observed 2026-08-28T04:10:21.096347+00:00)

## What it is
A curated collection of Chinese-community-maintained wordlists for web penetration testing, covering parameters, XSS payloads, usernames, passwords, directories, SQLi, SSRF, XXE, subdomains, and more. It is designed to be used with fuzzing tools like Burp Suite, wfuzz, and ffuf.

## Use cases
- brute force login forms with username and password wordlists
- fuzz hidden directories and files on a web server
- discover hidden API parameters
- test for XSS vulnerabilities with payload lists
- enumerate subdomains during reconnaissance
- find default credentials for routers and security appliances

## When to choose
- you need a comprehensive, categorized set of fuzzing dictionaries for web pentesting
- you want wordlists tuned for Chinese web applications and common Chinese passwords
- you use tools like Burp Intruder, wfuzz, or ffuf and need payload sources

## When to avoid
- you need actively maintained wordlists with frequent updates
- you require a license-clarified redistribution of the data
- you need non-web fuzzing dictionaries (e.g., binary or protocol fuzzing)

## Facets
- artifact type: dataset
- maturity: maintenance
- function: fuzzing, security, penetration-testing
- domain: security, penetration-testing, web-development
- platform: cross-platform
- tags: wordlists, dictionary, brute-force, pentesting, burpsuite, wfuzz

## Member repositories
- TheKingOfDuck/fuzzDicts (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:21.096347+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:27:16.468236+00:00, confidence not recorded.
  - readme: https://github.com/TheKingOfDuck/fuzzDicts (fetched 2026-08-28T04:10:21.096347+00:00, sha 17da30fe648a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
