Ross ROSS = Recommend OSS · open-source software intelligence for agents

riramar/Web-Attack-Cheat-Sheet resource

Web Attack Cheat Sheet observed · 2026-08-28

github.com/riramar/Web-Attack-Cheat-Sheet observed · 2026-08-28

Health v2 · maintenance only

76/100

  • Activity 98
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2426
  • days_rel: n/a
  • days_push: 17
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

4433 stars · 672 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A curated cheat sheet of tools, techniques, and resources for web application attacks, covering discovery, enumeration, scanning, and exploitation. It organizes links across categories like SQL injection, XSS, SSRF, subdomain takeover, and bug bounty reconnaissance.

Use cases

  • find tools for web application penetration testing
  • learn common web attack techniques like SQLi and XSS
  • reconnaissance resources for bug bounty hunting
  • find wordlists and tools for directory bruteforcing
  • reference payloads for SSRF and XXE attacks
  • discover subdomain enumeration and takeover tools

When to choose

  • you need a quick reference of offensive web security tools and techniques
  • you are preparing for bug bounty or pentest engagements
  • you want a curated starting point for learning web attacks

When to avoid

  • you need defensive security guidance or secure coding practices
  • you want a runnable tool rather than a list of links
  • you need a formal training course with structured lessons

Facets

learning-resource · maturity active

penetration-testing security osint vulnerability-scanning security penetration-testing web-development awesome-lists cli cross-platform cheat-sheet bug-bounty web-security offensive-security curated-list sqli xss ssrf web-server

1 source

Member repositories

RepositoryRoleHealth v2
riramar/Web-Attack-Cheat-Sheetmain76

For agents

markdown · JSON · MCP: product_card(name="riramar/Web-Attack-Cheat-Sheet")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem