# trickest/wordlists

Real-world infosec wordlists, updated regularly

Repository: https://github.com/trickest/wordlists
Canonical: https://ross.abutalabs.com/products/trickest-wordlists
Homepage: https://trickest.com
License: MIT
License Family: permissive
Topics: bugbounty, content-discovery, directory-bruteforce, hacking, infosec, penetration-testing, pentesting, reconnaissance, security, wordlist, wordlist-generator, wordlists, wordlists-dictionary-collection
Last push: 2026-08-26T13:10:57+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 35, longevity 100
- inputs: {"age_days": 1484, "days_push": 7, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1791, forks 207 (observed 2026-08-28T04:05:37.085656+00:00)

## What it is
A regularly updated collection of real-world infosec wordlists maintained by Trickest, including technology-specific path lists (WordPress, Joomla, Drupal, Magento, Ghost, Tomcat), robots.txt-derived paths from top websites, and subdomain wordlists from bug bounty programs and SSL certificates. It is a data repository rather than a tool, intended to feed fuzzing and enumeration tools.

## Use cases
- find wordlists for directory bruteforce during a pentest
- get content discovery wordlists for bug bounty hunting
- need a subdomain wordlist built from real bug bounty data
- find technology-specific path wordlists for WordPress or Tomcat
- want robots.txt-derived wordlists from top websites
- need regularly updated wordlists for fuzzing tools like ffuf or gobuster

## When to choose
- you need real-world, regularly refreshed wordlists for content discovery or subdomain enumeration
- you want technology-specific path lists derived from actual CMS/framework source code
- you need curated subdomain lists sourced from bug bounty programs and SSL certificates

## When to avoid
- you need a wordlist generator tool rather than prebuilt lists
- you need general-purpose password cracking wordlists like rockyou
- you require wordlists for non-web attack surfaces such as SSH or databases

## Facets
- artifact type: dataset
- maturity: active
- function: security, penetration-testing, web-scraping, data-generation
- domain: security, penetration-testing, crawlers
- platform: cross-platform, cli
- tags: wordlists, bugbounty, content-discovery, directory-bruteforce, reconnaissance, subdomain-enumeration, infosec

## Member repositories
- trickest/wordlists (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:37.085656+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:23:09.743805+00:00, confidence not recorded.
  - readme: https://github.com/trickest/wordlists (fetched 2026-08-28T04:05:37.085656+00:00, sha a9e85e77f529)
  - homepage: https://trickest.com (fetched 2026-08-29T11:02:29.885826+00:00, sha e7343ce3c591)
  - site_page: https://trickest.com/docs/introduction (fetched 2026-08-29T11:02:29.896578+00:00, sha ce06621f5c50)
  - site_page: https://trickest.com/docs/releases/changelog (fetched 2026-08-29T11:02:29.898309+00:00, sha 9027fd231153)
  - site_page: https://trickest.com/about-us (fetched 2026-08-29T11:02:29.902080+00:00, sha a4955c35541b)
  - site_page: https://trickest.com/pricing (fetched 2026-08-29T11:02:29.894957+00:00, sha dd1333d2be9e)
  - site_page: https://trickest.com/platform/cli (fetched 2026-08-29T11:02:29.903751+00:00, sha b82aef12b4ca)
- Data as of 2026-08-30T08:39:29.467469+00:00.
