Ross ROSS = Recommend OSS · open-source software intelligence for agents

m14r41/PentestingEverything resource

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc... observed · 2026-08-28

github.com/m14r41/PentestingEverything · homepage · TypeScript · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

83/100

  • Activity 98
  • Release rhythm 57
  • Longevity 95
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1340
  • days_rel: 75
  • days_push: 17
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

2044 stars · 458 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A structured penetration testing knowledge base covering 23 security domains (web, mobile, API, cloud, network, Active Directory, SAST, DevSecOps, and more) with 100+ documentation pages, reference PDFs, and 200+ curated tools, browsable via a live website. It also ships as an installable Agent Skill so AI coding agents like Cursor or Claude Code can use the knowledge base during security engagements.

Use cases

  • learn web application penetration testing with OWASP-based methodology
  • find the right tools for API pentesting and authorization testing
  • get a step-by-step guide for Android and iOS mobile pentesting
  • study source code review and SAST techniques
  • prepare for VAPT engagements with structured checklists
  • use a pentesting knowledge base from an AI coding agent
  • learn cloud and Active Directory pentesting fundamentals

When to choose

  • you need a single organized reference across many pentesting domains instead of scattered blog posts
  • you are a beginner or intermediate tester following OWASP-aligned methodologies
  • you want curated tool lists and reference PDFs per testing area
  • you want an agent-consumable security knowledge base for Cursor or Claude Code

When to avoid

  • you need an actual scanning or exploitation tool rather than documentation and guides
  • you require vendor-certified training or compliance-recognized course material
  • you need deep, exhaustive coverage of a single niche domain beyond the overview-level pages

Facets

learning-resource · maturity active

penetration-testing vulnerability-scanning security osint documentation developer-tools security penetration-testing osint developer-tools tutorials cli cross-platform vapt appsec pentesting-guide checklist knowledge-base owasp devsecops sast dast agent-skill web-server

10 sources

Member repositories

RepositoryRoleHealth v2
m14r41/PentestingEverythingmain83

For agents

markdown · JSON · MCP: product_card(name="m14r41/PentestingEverything")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem