{"adoption": {"forks": 326, "observed_at": "2026-08-28T04:06:12.595122+00:00", "stars": 2093}, "canonical_url": "https://ross.abutalabs.com/products/smuggler", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3", "domain": ["security", "penetration-testing", "web-development"], "enriched": true, "function": ["penetration-testing", "security", "http-client"], "health_score": 20, "homepage": null, "language": "Python", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["defparam/smuggler"], "name": "defparam/smuggler", "platform": ["python", "cli", "cross-platform"], "pushed_at": "2024-01-02T12:46:17+00:00", "repo": "defparam/smuggler", "stars": 2093, "tags": ["http-request-smuggling", "http-desync", "web-security", "bug-bounty", "pentesting", "vulnerability-detection", "python3", "te-cl", "cl-te", "recon"], "topics": [], "urls": [], "use_cases": ["test a website for http request smuggling vulnerabilities", "check if my reverse proxy or load balancer is vulnerable to http desync", "scan a list of hosts for cl.te and te.cl desync issues", "find request smuggling bugs in bug bounty targets", "detect front-end/back-end http header parsing mismatches", "audit cdn or api gateway endpoints for desync before deployment"], "what_it_is": "Smuggler is a Python 3 command-line tool that tests web servers and proxies for HTTP request smuggling and desync vulnerabilities. It fires a battery of mutated HTTP requests at a target URL or a piped list of hosts and flags responses that indicate potential front-end/back-end desync issues.", "when_to_avoid": ["you need a general-purpose web vulnerability scanner covering SQLi, XSS, etc. - smuggler only targets desync", "you require guaranteed accuracy - the author explicitly warns of false positives on large providers like AWS, Akamai, and Google", "you need a passive scanner - it actively sends malformed requests and can affect targets", "you lack authorization to test the target, since smuggling probes may disrupt services"], "when_to_choose": ["you need a quick, scriptable CLI check for HTTP request smuggling on one URL or thousands of piped hosts", "you are doing a pentest or bug bounty engagement and want Kettle-style desync mutations out of the box", "you want customizable payload sets via a config file, virtual host support, and logging of findings", "you need a lightweight Python 3 tool with no heavy dependencies"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/smuggler", "repo": "defparam/smuggler", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:06:12.595122+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:55:27.816200+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "187dbf639b71fd4457984f112788bfd022822f203cc70a9e52753fa4db890788", "fetched_at": "2026-08-28T04:06:12.595122+00:00", "kind": "readme", "missing": false, "url": "https://github.com/defparam/smuggler"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2277, "days_push": 974, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}