# F6JO/RouteVulScan

Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件

Repository: https://github.com/F6JO/RouteVulScan
Canonical: https://ross.abutalabs.com/products/routevulscan
Language: Java
License Family: other
Last push: 2026-07-10T04:28:46+00:00

## Health v2 (maintenance only)
Score: 82/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 91, release rhythm 60, longevity 100
- inputs: {"age_days": 1554, "days_push": 54, "days_rel": 54, "gap_med": null, "n_releases_24m": 1}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1334, forks 85 (observed 2026-08-28T04:04:25.184365+00:00)

## What it is
RouteVulScan is a Burp Suite extension written in Java that passively and recursively probes each path layer of web traffic for vulnerable routes, matching responses against configurable regex rules. It sends a small number of accurate payloads to uncover easily-overlooked vulnerabilities that path brute-forcing would miss.

## Use cases
- detect vulnerable paths on a website while browsing it through burp
- find sensitive files or endpoints hidden at any path depth
- passively scan burp traffic for weak routes without brute forcing
- customize regex rules to match specific vulnerability responses
- actively scan a target site's sitemap paths from a selected request

## When to choose
- you already use Burp Suite and want passive recursive path vulnerability detection
- you want low-noise, accurate probes instead of large wordlist brute-forcing
- you need customizable regex rules and host whitelisting for scoped testing

## When to avoid
- you need a standalone scanner outside of Burp Suite
- you require a license or official support - the project has no license file
- you need comprehensive active scanning with large payload dictionaries

## Facets
- artifact type: plugin
- maturity: active
- function: vulnerability-scanning, penetration-testing, security
- domain: security, penetration-testing, web-development, developer-tools
- platform: jvm, cross-platform
- tags: burpsuite-extension, passive-scanning, vulnerability-scanner, web-security, path-scanning, regex-matching

## Member repositories
- F6JO/RouteVulScan (main) score 82

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:25.184365+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:44:27.502135+00:00, confidence not recorded.
  - readme: https://github.com/F6JO/RouteVulScan (fetched 2026-08-28T04:04:25.184365+00:00, sha 18269de5cf11)
- Data as of 2026-08-30T08:39:29.467469+00:00.
