{"adoption": {"forks": 186, "observed_at": "2026-08-28T04:05:12.496417+00:00", "stars": 1621}, "canonical_url": "https://ross.abutalabs.com/products/sstimap", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Automatic SSTI detection tool with interactive interface", "domain": ["security", "penetration-testing", "web-development"], "enriched": true, "function": ["penetration-testing", "security", "web-scraping"], "health_score": 100, "homepage": null, "language": "Python", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["vladko312/SSTImap"], "name": "vladko312/SSTImap", "platform": ["python", "cli", "cross-platform"], "pushed_at": "2026-08-25T23:06:40+00:00", "repo": "vladko312/SSTImap", "stars": 1621, "tags": ["ssti", "template-injection", "rce", "exploitation", "pentest-tool", "tplmap-fork", "interactive-shell"], "topics": ["information-security", "penetration-testing", "penetration-testing-tools", "pentest", "pentest-tool", "pentesting", "pentesting-tools", "rce", "ssti", "python"], "urls": [], "use_cases": ["detect server-side template injection vulnerabilities in a website", "exploit SSTI to get remote code execution during a pentest", "run shell commands through an eval-like code injection", "test web forms and parameters for template injection", "identify which template engine a web app uses", "perform blind SSTI detection and file upload exploitation"], "what_it_is": "SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code injection vulnerabilities in web applications. It is an actively maintained fork of Tplmap with an interactive exploitation mode, additional detection techniques, and support for template engines across Java, JavaScript, PHP, Python, and Ruby.", "when_to_avoid": ["you need a Burp Suite extension (currently removed)", "you require Tplmap backwards-compatible command-line arguments", "you are looking for a general web vulnerability scanner beyond SSTI/code injection", "you cannot legally test the target system"], "when_to_choose": ["you are doing authorized penetration testing of web applications for SSTI/RCE", "you want an interactive shell for exploiting template injection", "you need broad template engine coverage including blind injection scenarios", "you want a maintained Python 3 alternative to Tplmap"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/sstimap", "repo": "vladko312/SSTImap", "role": "main", "score": 88}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:12.496417+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:49:16.046233+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0043ccc33318ada65c07225e7f8e96ee92c73b274c0aab74740f1a509a4d5d9a", "fetched_at": "2026-08-28T04:05:12.496417+00:00", "kind": "readme", "missing": false, "url": "https://github.com/vladko312/SSTImap"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 67}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1540, "days_push": 8, "days_rel": 8, "gap_med": 371, "n_releases_24m": 2}, "score": 88, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}