PortSwigger/param-miner
None observed · 2026-08-28
Health v2 · maintenance only
78/100
- Activity 97
- Release rhythm 40
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 5
- age_days: 2960
- days_rel: 723
- days_push: 20
- n_releases_24m: 2
Adoption not part of the score
1460 stars · 186 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary search to guess up to 65,000 parameter names per request. It is particularly useful for discovering web cache poisoning vulnerabilities and supports scalable, automated mining of in-scope traffic.
Use cases
- find hidden parameters in http requests
- discover web cache poisoning vulnerabilities
- brute force unlinked request headers and cookies
- mine parameters from all in-scope burp traffic automatically
- audit web applications for cache entanglement issues
- run scalable parameter guessing attacks on thousands of requests
When to choose
- you use Burp Suite and need to uncover hidden parameters, headers, or cookies
- you are hunting web cache poisoning or web cache entanglement bugs
- you need scalable, automated parameter discovery during penetration tests or bug bounty work
When to avoid
- you do not use Burp Suite
- you need a standalone scanner outside of Burp's proxy workflow
- your target cannot tolerate the request volume of parameter guessing attacks
Facets
plugin · maturity active
security penetration-testing developer-tools security penetration-testing web-development cross-platform jvm burp-suite-extension web-cache-poisoning parameter-discovery vulnerability-scanning bug-bounty
9 sources
- readme: https://github.com/PortSwigger/param-miner · fetched 2026-08-28 · dbc095726d15
- homepage: https://portswigger.net/blog/practical-web-cache-poisoning · fetched 2026-08-29 · 2602652c46e6
- site_page: https://portswigger.net/about · fetched 2026-08-29 · 169c41376de5
- site_page: https://portswigger.net/burp/documentation · fetched 2026-08-29 · 81bf81a32b5c
- site_page: https://portswigger.net/burp/documentation/desktop/getting-started · fetched 2026-08-29 · 65c8225eb7bb
- site_page: https://portswigger.net/burp/documentation/dast/setup · fetched 2026-08-29 · 61320640eca8
- site_page: https://portswigger.net/about/contact · fetched 2026-08-29 · 92c2df0aac75
- site_page: https://portswigger.net/support/reseller-faqs · fetched 2026-08-29 · 9ecd32d4698e
- site_page: https://portswigger.net/burp/releases · fetched 2026-08-29 · d83cfa415479
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| PortSwigger/param-miner | main | 78 |
For agents
markdown · JSON · MCP: product_card(name="PortSwigger/param-miner")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem