Ross ROSS = Recommend OSS · open-source software intelligence for agents

wallarm/jwt-secrets resource

None observed · 2026-08-28

github.com/wallarm/jwt-secrets · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

37/100

  • Activity 11
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2191
  • days_rel: n/a
  • days_push: 539
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1136 stars · 211 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A curated wordlist of thousands of publicly leaked JWT signing secrets, collected via Google dorks and GitHub BigQuery scans. It is used for detecting weak JWT secrets through traffic analysis and integrates with the JWT heartbreaker Burp extension.

Use cases

  • brute-force JWT signing secrets during penetration tests
  • detect weak JWT secrets in API traffic with a WAF
  • test whether my app's JWT secret is guessable
  • feed a JWT secret wordlist into Burp Suite
  • audit token security for hardcoded secrets

When to choose

  • you need a comprehensive list of known leaked JWT secrets for security testing
  • you use Wallarm NGWAF or the JWT heartbreaker Burp extension

When to avoid

  • you need a general-purpose password cracking wordlist
  • you want a tool rather than a static dataset

Facets

dataset · maturity maintenance

security penetration-testing vulnerability-scanning security developer-tools apis cross-platform jwt wordlist secrets brute-force burp-extension

1 source

Member repositories

RepositoryRoleHealth v2
wallarm/jwt-secretsmain37

For agents

markdown · JSON · MCP: product_card(name="wallarm/jwt-secrets")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem