# foospidy/payloads

Git All the Payloads! A collection of web attack payloads.

Repository: https://github.com/foospidy/payloads
Canonical: https://ross.abutalabs.com/products/payloads
Language: Shell
License: GPL-3.0
License Family: copyleft
Topics: payload, payloads, xss, sqli, web-attack-payloads, passwords, pentest, hacking, appsec, cybersecurity
Last push: 2023-05-15T21:54:24+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3846, "days_push": 1206, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3979, forks 990 (observed 2026-08-28T04:08:30.989347+00:00)

## What it is
A curated collection of web attack payloads (XSS, SQLi, CRLF, open redirect, password lists, and more) aggregated from many well-known security repositories and OWASP projects. A shell script downloads and unzips external payload sources into a unified local collection.

## Use cases
- find xss payloads for penetration testing
- get sql injection payload lists
- download wordlists for fuzzing web apps
- collect default password lists for testing
- build a local payload library for burp intruder
- find open redirect and crlf injection payloads

## When to choose
- you want one aggregated collection of many popular payload and wordlist sources
- you need payloads for manual pentesting or fuzzing tools like Burp Intruder or wfuzz

## When to avoid
- you need an active scanning tool rather than static payload data
- you need payloads for non-web attack categories like binary exploitation

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, penetration-testing, fuzzing, data-generation
- domain: security, penetration-testing, developer-tools
- platform: cli, windows
- tags: payloads, xss, sqli, wordlists, fuzzdb, seclists, appsec, pentest, attack-payloads, curated-collection, linux, macos

## Member repositories
- foospidy/payloads (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:30.989347+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:24:17.985402+00:00, confidence not recorded.
  - readme: https://github.com/foospidy/payloads (fetched 2026-08-28T04:08:30.989347+00:00, sha 21a0f673255c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
