wallarm/jwt-secrets resource
None observed · 2026-08-28
Health v2 · maintenance only
37/100
- Activity 11
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2191
- days_rel: n/a
- days_push: 539
- n_releases_24m: 0
Adoption not part of the score
1136 stars · 211 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A curated wordlist of thousands of publicly leaked JWT signing secrets, collected via Google dorks and GitHub BigQuery scans. It is used for detecting weak JWT secrets through traffic analysis and integrates with the JWT heartbreaker Burp extension.
Use cases
- brute-force JWT signing secrets during penetration tests
- detect weak JWT secrets in API traffic with a WAF
- test whether my app's JWT secret is guessable
- feed a JWT secret wordlist into Burp Suite
- audit token security for hardcoded secrets
When to choose
- you need a comprehensive list of known leaked JWT secrets for security testing
- you use Wallarm NGWAF or the JWT heartbreaker Burp extension
When to avoid
- you need a general-purpose password cracking wordlist
- you want a tool rather than a static dataset
Facets
dataset · maturity maintenance
security penetration-testing vulnerability-scanning security developer-tools apis cross-platform jwt wordlist secrets brute-force burp-extension
1 source
- readme: https://github.com/wallarm/jwt-secrets · fetched 2026-08-28 · b1940561455b
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| wallarm/jwt-secrets | main | 37 |
For agents
markdown · JSON · MCP: product_card(name="wallarm/jwt-secrets")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem