{"adoption": {"forks": 656, "observed_at": "2026-08-28T04:05:03.687133+00:00", "stars": 1559}, "canonical_url": "https://ross.abutalabs.com/products/qrljacking", "card": {"archived": false, "artifact_type": "framework", "description": " QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.", "domain": ["security", "penetration-testing", "web-development"], "enriched": true, "function": ["security", "penetration-testing", "web-scraping"], "health_score": 41, "homepage": null, "language": "Python", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["OWASP/QRLJacking"], "name": "OWASP/QRLJacking", "platform": ["python", "windows", "cli"], "pushed_at": "2025-08-07T21:07:19+00:00", "repo": "OWASP/QRLJacking", "stars": 1559, "tags": ["qrljacking", "session-hijacking", "social-engineering", "qr-code", "exploitation-framework", "owasp", "linux", "macos"], "topics": [], "urls": [], "use_cases": ["demonstrate QR code login session hijacking", "test whether an app's login-with-QR feature is vulnerable", "run social engineering awareness demos", "perform penetration tests on QR-based authentication flows", "study the QRLJacking attack vector from the technical paper"], "what_it_is": "QRLJacking is an OWASP project documenting and exploiting the Quick Response Code Login Jacking attack vector, which hijacks user sessions on apps that rely on 'Login with QR code'. It includes QRLJacker, a Python-based exploitation framework for demonstrating the attack.", "when_to_avoid": ["you want a defensive library to fix QR login vulnerabilities", "you need a production authentication solution", "you lack authorization to test the target application"], "when_to_choose": ["you are a security researcher or pentester assessing QR-code login flows", "you need a reference implementation and documentation of the QRLJacking attack", "you want to raise awareness of QR login session hijacking risks"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/qrljacking", "repo": "OWASP/QRLJacking", "role": "main", "score": 48}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:03.687133+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:29:48.841776+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6dcbe063d6f928b3657564d2aa3ec588f18ad527570f3de51b4207ff6be53f5e", "fetched_at": "2026-08-28T04:05:03.687133+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/QRLJacking"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 35, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3705, "days_push": 391, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 48, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}