Ross ROSS = Recommend OSS · open-source software intelligence for agents

r0oth3x49/ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws observed · 2026-08-28

github.com/r0oth3x49/ghauri · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

54/100

  • Activity 45
  • Release rhythm 38
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 47
  • age_days: 1432
  • days_rel: 333
  • days_push: 333
  • n_releases_24m: 6

Full methodology

Adoption not part of the score

4070 stars · 422 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Ghauri is a cross-platform Python CLI tool that automates detection and exploitation of SQL injection vulnerabilities in web applications. It supports boolean, error, time-based, and stacked-query injection techniques against MySQL, MSSQL, Postgres, Oracle, and Access, across GET/POST, headers, cookies, JSON, and SOAP/XML inputs.

Use cases

  • detect sql injection vulnerabilities in a web app
  • automate sql injection testing like sqlmap
  • extract database data via blind sql injection
  • test json and soap endpoints for sqli
  • inject payloads via http headers and cookies
  • resume an interrupted sql injection session

When to choose

  • you need a modern, actively maintained sqlmap alternative
  • you need JSON, SOAP/XML, or multipart form injection support
  • you want proxy support and resumable extraction phases

When to avoid

  • you need a GUI-based vulnerability scanner
  • you need broad DBMS coverage beyond the supported engines
  • you need general web vulnerability scanning beyond SQLi

Facets

cli-tool · maturity active

penetration-testing security cli security penetration-testing databases developer-tools python windows cli cross-platform sql-injection sqlmap-alternative exploitation web-security database-exploitation pentesting linux macos

1 source

Member repositories

RepositoryRoleHealth v2
r0oth3x49/ghaurimain54

For agents

markdown · JSON · MCP: product_card(name="r0oth3x49/ghauri")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem