# Az0x7/vulnerability-Checklist

This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter

Repository: https://github.com/Az0x7/vulnerability-Checklist
Canonical: https://ross.abutalabs.com/products/vulnerability-checklist
License Family: other
Topics: bugbounty, security, sqlinjection, vulnerability, vulnerability-checklist, web-vulnerability
Last push: 2024-02-10T18:51:57+00:00

## Health v2 (maintenance only)
Score: 30/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 87
- inputs: {"age_days": 1227, "days_push": 935, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3634, forks 843 (observed 2026-08-28T04:08:12.633876+00:00)

## What it is
A curated collection of web and API vulnerability checklists covering topics like IDOR, SQL injection, 2FA bypass, account takeover, and 403 bypass. It aggregates vulnerability ideas and tips from the bug bounty community, especially Twitter.

## Use cases
- find a checklist for testing IDOR vulnerabilities
- learn 2FA bypass techniques for bug bounty hunting
- prepare for a web application penetration test
- look up SQL injection testing tips
- study account takeover attack vectors
- find 403 bypass methods
- collect bug bounty tips from Twitter

## When to choose
- you are a bug bounty hunter or pentester needing structured checklists for common web vulnerabilities
- you want community-sourced tips and attack ideas in one place
- you need a quick reference during a security assessment

## When to avoid
- you need an automated vulnerability scanner rather than manual checklists
- you require formally reviewed or vendor-backed security guidance
- you need a tool that runs tests rather than documents them

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, vulnerability-scanning
- domain: security, penetration-testing, developer-tools
- platform: cli
- tags: bug-bounty, checklist, web-vulnerabilities, api-security, idor, sql-injection, 2fa-bypass, account-takeover, web-server

## Member repositories
- Az0x7/vulnerability-Checklist (main) score 30

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:12.633876+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:31:50.825634+00:00, confidence not recorded.
  - readme: https://github.com/Az0x7/vulnerability-Checklist (fetched 2026-08-28T04:08:12.633876+00:00, sha e3bb736f6dc5)
- Data as of 2026-08-30T08:39:29.467469+00:00.
