Ross ROSS = Recommend OSS · open-source software intelligence for agents

h4r5h1t/webcopilot

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities. observed · 2026-08-28

github.com/h4r5h1t/webcopilot · Shell · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1830
  • days_rel: n/a
  • days_push: 776
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1295 stars · 203 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

WebCopilot is a Bash-based automation script for bug bounty reconnaissance that enumerates subdomains using multiple tools, filters parameters vulnerable to XSS, SQLi, open redirect, LFI, SSRF, and RCE, and scans for vulnerabilities with tools like dalfox and nuclei. It orchestrates a pipeline of open-source security tools and saves all output to a specified directory.

Use cases

  • automate subdomain enumeration for a target domain
  • find XSS and SQLi parameters across subdomains
  • run a full recon and vulnerability scan pipeline for bug bounty
  • check for subdomain takeover
  • crawl endpoints from wayback and filter by vulnerability patterns
  • scan a domain for SSRF, LFI, and open redirect bugs

When to choose

  • you want a one-command recon-to-vuln-scan pipeline for bug bounty targets
  • you already use tools like subfinder, amass, httpx, and nuclei and want them chained automatically
  • you need organized output files from a multi-tool recon workflow

When to avoid

  • you need a maintained, production-grade vulnerability scanner with support
  • you are on Windows without WSL or a Unix-like shell
  • you want a GUI or interactive web interface
  • you need authorized enterprise security testing with reporting features

Facets

cli-tool · maturity active

security penetration-testing web-scraping cli workflow-automation security penetration-testing developer-tools cli bug-bounty recon subdomain-enumeration vulnerability-scanning reconnaissance bash-script offensive-security command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
h4r5h1t/webcopilotmain23

For agents

markdown · JSON · MCP: product_card(name="h4r5h1t/webcopilot")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem