Ross ROSS = Recommend OSS · open-source software intelligence for agents

vladko312/SSTImap

Automatic SSTI detection tool with interactive interface observed · 2026-08-28

github.com/vladko312/SSTImap · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

88/100

  • Activity 99
  • Release rhythm 67
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 371
  • age_days: 1540
  • days_rel: 8
  • days_push: 8
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

1621 stars · 186 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code injection vulnerabilities in web applications. It is an actively maintained fork of Tplmap with an interactive exploitation mode, additional detection techniques, and support for template engines across Java, JavaScript, PHP, Python, and Ruby.

Use cases

  • detect server-side template injection vulnerabilities in a website
  • exploit SSTI to get remote code execution during a pentest
  • run shell commands through an eval-like code injection
  • test web forms and parameters for template injection
  • identify which template engine a web app uses
  • perform blind SSTI detection and file upload exploitation

When to choose

  • you are doing authorized penetration testing of web applications for SSTI/RCE
  • you want an interactive shell for exploiting template injection
  • you need broad template engine coverage including blind injection scenarios
  • you want a maintained Python 3 alternative to Tplmap

When to avoid

  • you need a Burp Suite extension (currently removed)
  • you require Tplmap backwards-compatible command-line arguments
  • you are looking for a general web vulnerability scanner beyond SSTI/code injection
  • you cannot legally test the target system

Facets

cli-tool · maturity active

penetration-testing security web-scraping security penetration-testing web-development python cli cross-platform ssti template-injection rce exploitation pentest-tool tplmap-fork interactive-shell

1 source

Member repositories

RepositoryRoleHealth v2
vladko312/SSTImapmain88

For agents

markdown · JSON · MCP: product_card(name="vladko312/SSTImap")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem