Ross ROSS = Recommend OSS · open-source software intelligence for agents

xnl-h4ck3r/GAP-Burp-Extension

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist observed · 2026-08-28

github.com/xnl-h4ck3r/GAP-Burp-Extension · Python observed · 2026-08-28

Health v2 · maintenance only

66/100

  • Activity 61
  • Release rhythm 53
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 45
  • age_days: 1931
  • days_rel: 237
  • days_push: 237
  • n_releases_24m: 10

Full methodology

Adoption not part of the score

1530 stars · 159 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

GAP is a Burp Suite extension written in Python (Jython) that extracts potential endpoints, parameters, and links from Burp's site map, proxy history, and responses. It also generates a target-specific custom wordlist for use in fuzzing.

Use cases

  • find hidden parameters on a web target during a bug bounty
  • extract potential endpoints from Burp site map and proxy history
  • generate a custom wordlist for fuzzing a specific target
  • discover links to test parameters on during web app pentesting
  • collect parameter names from HTTP responses for manual investigation

When to choose

  • you already use Burp Suite and want in-tool endpoint/parameter discovery
  • you need a target-specific wordlist for fuzzing tools like ffuf or wfuzz
  • you're doing manual web application security testing or bug bounty recon

When to avoid

  • you need automated scanning rather than manual extraction and analysis
  • you don't use Burp Suite or can't set up a Jython environment
  • you need a standalone CLI recon tool outside of Burp

Facets

plugin · maturity active

web-scraping security developer-tools parser security penetration-testing web-development developer-tools cross-platform jvm python burp-extension bug-bounty recon wordlist-generation parameter-discovery endpoint-discovery fuzzing jython

1 source

Member repositories

RepositoryRoleHealth v2
xnl-h4ck3r/GAP-Burp-Extensionmain66

For agents

markdown · JSON · MCP: product_card(name="xnl-h4ck3r/GAP-Burp-Extension")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem