# xnl-h4ck3r/GAP-Burp-Extension

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

Repository: https://github.com/xnl-h4ck3r/GAP-Burp-Extension
Canonical: https://ross.abutalabs.com/products/gap-burp-extension
Language: Python
License Family: other
Last push: 2026-01-08T19:23:17+00:00

## Health v2 (maintenance only)
Score: 66/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 61, release rhythm 53, longevity 100
- inputs: {"age_days": 1931, "days_push": 237, "days_rel": 237, "gap_med": 45, "n_releases_24m": 10}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1530, forks 159 (observed 2026-08-28T04:04:59.266414+00:00)

## What it is
GAP is a Burp Suite extension written in Python (Jython) that extracts potential endpoints, parameters, and links from Burp's site map, proxy history, and responses. It also generates a target-specific custom wordlist for use in fuzzing.

## Use cases
- find hidden parameters on a web target during a bug bounty
- extract potential endpoints from Burp site map and proxy history
- generate a custom wordlist for fuzzing a specific target
- discover links to test parameters on during web app pentesting
- collect parameter names from HTTP responses for manual investigation

## When to choose
- you already use Burp Suite and want in-tool endpoint/parameter discovery
- you need a target-specific wordlist for fuzzing tools like ffuf or wfuzz
- you're doing manual web application security testing or bug bounty recon

## When to avoid
- you need automated scanning rather than manual extraction and analysis
- you don't use Burp Suite or can't set up a Jython environment
- you need a standalone CLI recon tool outside of Burp

## Facets
- artifact type: plugin
- maturity: active
- function: web-scraping, security, developer-tools, parser
- domain: security, penetration-testing, web-development, developer-tools
- platform: cross-platform, jvm, python
- tags: burp-extension, bug-bounty, recon, wordlist-generation, parameter-discovery, endpoint-discovery, fuzzing, jython

## Member repositories
- xnl-h4ck3r/GAP-Burp-Extension (main) score 66

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:59.266414+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:31:26.343273+00:00, confidence not recorded.
  - readme: https://github.com/xnl-h4ck3r/GAP-Burp-Extension (fetched 2026-08-28T04:04:59.266414+00:00, sha f878076c7c79)
- Data as of 2026-08-30T08:39:29.467469+00:00.
